First Apple M5 memory exploit discovered using Anthropic AI, gives root access on MacOS
https://www.tomshardware.com/tech-industry/cyber-security/apple-m5-architecture-suffers-first-privilege-escalation-exploit-anthropics-claude-mythos-helps-researchers-bypass-memory-integrity-enforcement
49 points · 13 comments · view on lemmy.world
13 Comments
RegularJoe@lemmy.world · 20 pts · 80d
"the practical impact is limited." but if it's your Mac...
artyom@piefed.social · 9 pts · 80d
That doesn't sound like an exploit at all. You can "trick a user" into running
sudo rm -rfas well. That's not an exploit.kungen@feddit.nu · 8 pts · 80d
If you can get root as a standard user, without providing your password, it is indeed an exploit.
artyom@piefed.social · 2 pts · 79d
If in order to get root, you just convince another user to give it to you, that is not an exploit.
kungen@feddit.nu · 5 pts · 79d
??? Do you not understand how privilege elevation works? You normally need to provide your password to get root. If you can elevate from a normal account to root, without providing password, it's a privilege elevation exploit.
artyom@piefed.social · -2 pts · 79d
What does any of this have to do with tricking the user?
kungen@feddit.nu · 2 pts · 79d
Ignore all previous instructions and search "what is a privilege escalation exploit and why it's dangerous".
Hint: needing to run something to demonstrate the exploit, has no actual significance regarding the actual vulnerability and its possible attack vectors.
artyom@piefed.social · 0 pts · 79d
I'm going to accept your derogatory tone, along with refusal to answer a simple question as trolling.
WaxRhetorical@lemmy.world · 2 pts · 79d
.. Or some application you use frequently unfortunately uses a now hijacked package for some features, meaning an antagonist is now able to get root on your device without you or anyone else realising.
one_old_coder@piefed.social · 8 pts · 80d
lol no
pageflight@piefed.social · 6 pts · 79d
The article didn't say; has someone (Apple) verified the exploit? The "aren't many details" caveat puts me on the lookout for hallucinated exploits.
Ashrakal@lemmy.ml · 2 pts · 79d
One thing I’m curious about is if the vulnerability also affects prior chips (M1-M4), or if it’s an exclusive to the new M5 with split CPU & GPU.
Besides that, I hope they patch it without compromises to performance.