Apple’s technical details on the many security fixes included in today’s operating system updates show how quickly AI tools are becoming part of vulnerability research. Here are the details.
Earlier today, Apple released:
As soon as the updates were rolled out, Apple updated its security releases page with more information on several of the issues addressed, including the affected components and devices, their potential impact, how Apple fixed them, and the researchers credited with reporting them.
One notable detail in today’s documents is their sheer length, especially considering that Apple released the 26.5.2 updates less than a month ago and said they included fixes originally planned for the 26.6 release cycle.
Another notable detail is that Anthropic researchers and Claude are credited with fixes involving WebKit, WebKit Storage, and WebDAV, some of which were made alongside researchers from Calif.io.
That is the same research team that said in May it had used Anthropic’s Mythos Preview model to help build a working macOS kernel memory corruption exploit on M5 silicon in just five days.
The Calif is credited for several kernel security fixes in every operating system update released today, alongside more than a dozen researchers credited for those vulnerabilities, suggesting that multiple teams independently reported the same underlying issues.
In fact, Apple addressed many other kernel vulnerabilities in this release cycle, with 30 distinct CVEs listed across all of today’s operating system updates.
It is also worth noting that Apple has had access to Claude Mythos Preview through Anthropic’s Project Glasswing since April. As a result, the number of vulnerabilities found internally with Claude could be higher than the public credits suggest.
Finally, Anthropic is not the only AI company represented in today’s notes. Apple also credits work involving OpenAI Codex Security, Z.AI’s GLM, and NVIDIA’s AI Red Team, among others.
... continue reading