Apple’s M5 MIE bypass: what the researchers demonstrated
Calif combined two macOS bugs to gain root on an M5 Mac while MIE remained enabled. Apple patched them in macOS 26.6. Here’s what the result says about memory tagging.
INSIGHTS & PRACTICAL GUIDANCE
Clear explanations and useful steps from Short Circuit LLC. For original vulnerability findings and advisories, explore our research ↗.
Calif combined two macOS bugs to gain root on an M5 Mac while MIE remained enabled. Apple patched them in macOS 26.6. Here’s what the result says about memory tagging.
The update addresses memory corruption and authorization flaws across Acrobat’s update tracks. Check the reader people use and the protections applied to outside documents.
Mozilla’s fixes cover Firefox 155 and two ESR branches. The advisories explain the risks, but checking the right update still starts with knowing which channel is installed.
Apple fixed an integer overflow in ImageIO. Here’s how image-size calculations can go wrong, what Apple has disclosed and why the operating-system update matters.
Four Apple, Google and Microsoft cases show why patch announcements and known-exploitation records belong in the same workflow, without treating either date as the start of an attack.
Google confirmed exploitation of a V8 type-confusion flaw. The advisory identifies the fix, but leaves the underlying failure and the rest of any exploit chain undisclosed.
A fraudulent payment request can pass SPF, DKIM and DMARC. Here’s what those checks establish, what evidence to keep, and how to verify the transaction itself.
CVSS, EPSS and known exploitation answer different questions. Use them alongside your own inventory and exposure, then verify that the fixed software is actually running.