logoalt Hacker News

SyneRydertoday at 8:39 AM5 repliesview on HN

> ... Anthropic's Project Glasswing is supposed to find them quite a while ago?

That was my thought too. For all of Anthropic's talk about their "adversaries", it seems Z.AI have been quietly offering fixes for single shot Remote Code Execution flaws in US software (Safari / WebKit) that Apple and Glasswing / Mythos missed, and that Apple would not attribute to GLM.


Replies

oefrhatoday at 11:44 AM

> and that Apple would not attribute to GLM

That was a wtf to me, so I checked Apple’s latest iOS release security content and GLM & z.ai is mentioned once (under WebKit), Anthropic is mentioned twice, Codex is mentioned once. Not clear if there are other instances where the model did most of the work but wasn’t credited. I didn’t bother to check other releases.

https://support.apple.com/en-us/128066

chvidtoday at 9:22 AM

Who says they missed them? Could also be sitting pretty in CIA’s long list of ready to go Vault7-like exploits.

stingraycharlestoday at 10:50 AM

> That was my thought too. For all of Anthropic's talk about their "adversaries"

It’s very likely they found all of them, but that the same happened that happened to Microsoft a couple of decades ago: NSA orders not to disclose / fix them so that they can put it in their collection of unfixed zero days.

tssstoday at 11:54 AM

Probably Anthropic found them too and promptly got a call from Isreal to stop looking.