Apple Patches 30+ iOS, macOS, Safari Flaws, Including AI-Discovered WebKit Bugs
17:30 · June 29, 2026 · Hacker News AI Section

Apple on Monday released security updates for iOS, macOS, and the Safari web browser to address over three dozen flaws, including four vulnerabilities in WebKit that were discovered using artificial intelligence (AI) tools like Anthropic Claude and OpenAI Codex Security. The WebKit vulnerabilities are listed below - CVE-2026-43707 - A memory corruption issue that could result in an
Summary
Apple has issued security updates across iOS 26.5.2, iPadOS 26.5.2, macOS Tahoe 26.5.2, and Safari 26.5.2 that address more than three dozen vulnerabilities. The fixes cover roughly thirty issues in WebKit, the open-source browser engine that underpins Safari and other Apple platforms, along with several kernel-level defects that could allow a malicious app to leak sensitive state, terminate the system unexpectedly, or corrupt memory.
Four of the WebKit flaws stand out because they were identified with the assistance of large language models. OpenAI Codex Security is credited for the first three, while researchers Milad Nasr and Nicholas Carlini, working with Anthropic’s Claude, are acknowledged for CVE-2026-43715. Additional WebKit issues include a use-after-free condition in the Canvas component (CVE-2026-43720) and a sandbox-escape vector (CVE-2026-43725) that could let a malicious site access restricted content. Security researcher Hyunwoo Kim reported two of the kernel bugs.
None of the patched vulnerabilities has been observed in active exploitation. Apple nevertheless shortened its usual disclosure-to-deployment window, citing the risk that AI tools could compress the time between discovery and weaponization of new exploits. The company stated that it is adapting its processes to the reality that artificial intelligence can accelerate the creation of malicious tooling, requiring faster delivery of patches to end users.
Why it matters
This article is highly relevant for security professionals as it demonstrates the practical application of AI models in discovering critical software vulnerabilities. It underscores the evolving landscape of AI-driven threat research and the immediate need for enterprises to patch affected Apple devices.








