Apple Patches 30+ Bugs Including AI-Discovered Flaws

Get the Tech newsletter
Daily tech — startups, AI labs, chips, the launches that shape the next decade. Free.
- Apple released security updates for iOS, macOS, and Safari on Monday addressing over 30 vulnerabilities, including four WebKit flaws discovered using AI tools.
- OpenAI Codex Security was credited by Apple for three of the four AI-discovered WebKit vulnerabilities — CVE-2026-43707, CVE-2026-43716, and CVE-2026-43745.
- Anthropic researchers Milad Nasr and Nicholas Carlini, alongside Claude, were acknowledged for CVE-2026-43715, a use-after-free memory corruption issue addressed with improved memory management.
- The WebKit engine saw nearly 30 total patches, including a Canvas use-after-free (CVE-2026-43720) and a sandbox-bypass flaw (CVE-2026-43725) that could let a malicious site process restricted content outside the sandbox.
- Security researcher Hyunwoo Kim was credited with discovering "Dirty Frag" and reporting two kernel-level bugs (CVE-2026-43724 and CVE-2026-43722) that could leak sensitive kernel state or corrupt kernel memory.
- Apple told Reuters it is now shipping patches earlier because AI has compressed the window between vulnerability discovery and weaponization to hours; none of the patched flaws have been disclosed as actively exploited in the wild.
Why it matters: Apple is publicly tying its patching cadence to AI-accelerated threats, shortening the gap between vulnerability disclosure and patch availability for iOS 26.5.2, iPadOS 26.5.2, macOS Tahoe 26.5.2, and Safari 26.5.2 users. The coordinated disclosure credits to OpenAI and Anthropic researchers mark AI labs functioning as formal vulnerability finders inside Apple's security pipeline.


