Apple Credits Claude, Codex, GLM in 30-CVE Patch

Get the Tech newsletter
Daily tech — startups, AI labs, chips, the launches that shape the next decade. Free.
- Apple released iOS 26.6, iPadOS 26.6, macOS Tahoe 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, tvOS 26.6, visionOS 26.6, and watchOS 26.6 on July 27, 2026, addressing 30 distinct CVEs across the OS family
- Anthropic researchers and Claude were credited for fixes involving WebKit, WebKit Storage, and WebDAV, some reported alongside Calif.io researchers
- Apple has had access to Claude Mythos Preview through Anthropic's Project Glasswing since April, meaning internal vulnerability discoveries using Claude could exceed public credits
- The Calif team said in May it used Anthropic's Mythos Preview model to build a working macOS kernel memory corruption exploit on M5 silicon in five days
- Apple also credited OpenAI Codex Security, Z.AI's GLM, and NVIDIA's AI Red Team in the same release notes
- Apple accelerated the 26.5.2 updates less than a month ago in response to AI-powered hacking risks, rolling in fixes originally planned for the 26.6 cycle
Why it matters: Apple credited at least four AI vendors—Anthropic, OpenAI, Z.AI, NVIDIA—for vulnerability discoveries in a single release cycle addressing 30 CVEs across eight operating systems. With multiple independent teams reporting the same kernel issues and bug-bounty programs forced to adapt, Apple is now operating on a faster patch cadence dictated by machine-speed research.




