Apple Credits Claude, Codex, NVIDIA in Security Fixes

Get the Tech newsletter
Daily tech — startups, AI labs, chips, the launches that shape the next decade. Free.
- Apple released iOS 26.6, iPadOS 26.6, macOS Tahoe 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, tvOS 26.6, visionOS 26.6, and watchOS 26.6 on July 27, 2026, addressing 30 distinct CVEs across all platforms.
- Anthropic researchers and Claude are credited with fixes involving WebKit, WebKit Storage, and WebDAV, some developed alongside researchers from Calif.io.
- The Calif research team is credited for several kernel security fixes in every operating system update released today—the same team that previously built a working macOS kernel memory corruption exploit on M5 silicon in five days using Anthropic's Mythos Preview.
- Apple has had access to Claude Mythos Preview through Anthropic's Project Glasswing since April, meaning vulnerabilities found internally with Claude may exceed what public credits show.
- Apple also credits work involving OpenAI's Codex Security, Z.AI's GLM, and NVIDIA's AI Red Team, broadening the roster of AI-assisted security research beyond Anthropic alone.
- Today's updates came less than a month after Apple's 26.5.2 release, which already pulled forward fixes originally planned for the 26.6 cycle—reflecting the compressed cadence AI-powered vulnerability discovery now demands.
Why it matters: With 30 CVEs addressed and credits spanning Anthropic, OpenAI, Z.AI, and NVIDIA, Apple now treats AI-assisted vulnerability discovery as routine rather than experimental. The compressed release window (26.5.2 shipped less than a month before 26.6, with originally-planned 26.6 fixes pulled forward) shows vendors must tighten update cadences and bug bounty structures to keep pace with model-accelerated security research.




