Claude discovers Apple macOS kernel vulnerability: CVE-2026-28952 and the era of AI security auditing
Claude (Anthropic Mythos) discovered a critical vulnerability in the Apple macOS kernel, CVE-2026-28952, which has been fixed in macOS Tahoe 26.5. This is the first time that AI-assisted kernel vulnerability discovery has appeared publicly in Apple's security acknowledgments, marking the entry of AI security auditing into production-level applications.
Core conclusion
On May 11, 2026, Apple fixed a critical kernel vulnerability (CVE-2026-28952) discovered by Claude (Anthropic) in the macOS Tahoe 26.5 security update. The security research team Calif.io discovered this integer overflow vulnerability with the help of the Mythos Preview model and successfully constructed a kernel exploit on the Apple M5 chip.
This incident marks the official entry of AI security auditing from a laboratory project into the production-level vulnerability discovery stage.
Key Points
- Vulnerability number: CVE-2026-28952, affecting iOS 18.7.9, macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.5
- Vulnerability type: Kernel integer overflow, which can cause the application to cause the system to terminate unexpectedly
- Discovered by: Calif.io team in collaboration with Claude (Mythos model)
- Repair time: Pushed on May 11, 2026, all versions have been repaired
- HN Discussion popularity: 129 points, 59 comments, focusing on the long-term impact of AI on the security industry
Background: Apple macOS security updates and Claude’s first public appearance
On May 11, 2026, Apple released a security update for macOS Tahoe 26.5 that fixed more than 40 security vulnerabilities. Among the many CVEs, CVE-2026-28952 is particularly eye-catching - its discoverer's column reads: Calif.io in collaboration with Claude and Anthropic Research.
This is the first time Anthropic's Claude (specifically the Mythos model) has publicly appeared in Apple's security credits.
According to HN community news, the Calif.io team worked with Mythos Preview to build a kernel memory corruption exploit targeting the Apple M5 chip within five days. However, core members of the team clarified on HN: CVE-2026-28952 is not related to their recently disclosed MIE attack - MIE exploited two different kernel vulnerabilities and has not been patched so far.
Key Impact: AI’s ability to discover vulnerabilities is reshaping the security industry landscape
| Dimensions | Change | What it means to us | Recommended actions |
|---|---|---|---|
| Vulnerability discovery speed | From weeks to days (5 days to build an exploit) | Security patch cycles must be shortened | Enable automatic updates and no longer lag behind one version |
| Discovery coverage | AI can scan the kernel code of multiple platforms simultaneously | The gap in traditional manual audits is quickly filled | Consider introducing AI-assisted security audit services |
| Industry competition | Google’s CodeMender, Anthropic’s Glasswing | Security capabilities have become the core indicator of AI model competitiveness | Comparison of security vulnerability discovery capabilities of models focusing on |
| Update strategy | The frequency of zero-day vulnerability discovery has increased significantly | It is no longer safe to update one version later | It is recommended to update to the latest version in time |
A comment from HN user vesselness sums up this shift perfectly:
I've been stuck on being one version behind for years, but last night I hit the update button for 26.5. It feels like FOMO, but with a security update.
The battlefield pattern of AI security audit
CVE-2026-28952 is not an isolated incident. Since 2026, AI-driven security auditing has become a focus battlefield for major manufacturers:
- Google's CodeMender (based on Mythos) has been put into Chrome security audits, fixing 302 vulnerabilities since mid-April alone, 225 of which were discovered by AI
- Anthropic's Project Glasswing discovers over 10,000 high-severity vulnerabilities in one month
- OpenAI's Codex Security has also previously demonstrated the ability of AI to automate security audits
Compared to the same period last year, when only 19 vulnerabilities were found in Chrome, AI-assisted vulnerability discoveries increased more than 10x. AI models are changing from "the object being audited" to "the auditor themselves".
Actual impact on developers and content operators
The update strategy must change
In the past, the strategy of "lagging behind one version for more stable updates" is no longer applicable in the era of AI security. Because AI can continuously scan source code repositories and discover vulnerabilities in batches, the frequency of discovery of zero-day vulnerabilities will increase significantly.
Suggestions:
- Upgrade to macOS Tahoe 26.5 or the corresponding iOS/iPadOS version as soon as possible
- Enable automatic security updates for iOS and macOS
- Follow the CVE list on Apple's Security Response page
AI Agent security deserves attention
With the popularity of AI Agents in programming, automation, content production and other fields, the security of the Agent itself has become a new topic. Calif.io specializes in researching AI Agent security vulnerabilities (MAD Bugs series), including in-depth audits of tools such as Claude Code, Codex, n8n, and more.
Tool entry (trigger tool floating card)
Key AI tools covered in the text: Claude, Claude Code, OpenAI, Codex, ChatGPT, n8n, Hermes Agent, DeepSeek
Reference sources
Internal link guidance
Want to learn how to use AI to build automated workflows? Watch: AI Agent drives automated website operations: Build a fully automatic content pipeline in 30 minutes
Real case: How security researchers use Claude Code to make monthly income from vulnerability mining $10,000: Security researcher uses Claude Code for vulnerability mining: a real case of monthly income $10,000
Topic hub
AI Coding Tools Hub (2026)
From Copilot pricing changes to Claude Code + DeepSeek cost-saving setups—one place to compare tools, read explainers, and follow tutorials.
Explore AI Coding Tools Hub (2026) →Monetization angle
How can you make money from this trend?
WayToClawEarn focuses on verified earn playbooks—not just news. Start from these cases.
DeepSeek + Claude Code Micro SaaS
Run multiple small products on cheap inference
Claude Code bug bounty
Productize agent skills into security services