Mark RadarMARK RADAR
About
EN
Sign in
Event File AI OpenAI Claude

Apple Patches More Than 30 Flaws, With AI Tools Helping Find Vulnerabilities for First Time

1 reports · First detected 2026-07-01 · Last active 2026-07-01

Apple’s iOS, macOS and Safari share core components including WebKit, meaning vulnerabilities could affect large numbers of smartphone and computer users and making regular security updates especially important. The case also highlights how generative AI has expanded beyond coding into vulnerability research, helping researchers analyze code and identify potential risks.

Apple recently released several security updates that patched more than 30 vulnerabilities in iOS, macOS and Safari. Four flaws in the WebKit browser engine were found with assistance from AI tools including Anthropic Claude and OpenAI Codex. This was also the first time Apple disclosed that AI tools had helped discover vulnerabilities.

All Coverage

1 original reports

The Backstory

The history behind this event
Apple Credits Claude, Codex in Sweeping Security Update2026-07-31 · 1 reports · similarity 0.91

Apple’s operating systems span phones, computers, watches and other devices, making flaws in the kernel and WebKit a broad security concern. Successful exploitation can lead to memory corruption, data exposure or application crashes. The latest acknowledgements are also notable because they name AI-assisted research involving Anthropic’s Claude and OpenAI’s Codex Security, showing that generative AI is moving beyond software development into vulnerability discovery and putting pressure on vendors to shorten patch cycles.

On July 27, 2026, Apple released iOS 26.6, iPadOS 26.6, macOS Tahoe 26.6, Safari 26.6 and updates for older macOS versions, tvOS, visionOS and watchOS. The release cycle listed 30 distinct kernel CVEs across Apple’s operating systems. Apple credited Anthropic researchers and Claude for work tied to WebKit, WebKit Storage and WebDAV, while Codex Security appeared in acknowledgements for WebKit Canvas alongside Calif.io, Z.AI’s GLM, NVIDIA’s AI Red Team and other security researchers.

Apple Patches 420 Flaws Across Three macOS Versions2026-07-29 · 1 reports · similarity 0.81

Apple’s simultaneous support for three macOS generations matters because many businesses and consumers remain on older Macs or delay major upgrades. Security releases for Tahoe, Sequoia and Sonoma address weaknesses in core components including the Kernel and WebKit, where flaws can enable privilege escalation, sandbox escapes, data exposure or malicious code execution. The breadth of the fixes also shows how AI-assisted research is accelerating vulnerability discovery.

Apple released macOS Tahoe 26.6, Sequoia 15.7.8 and Sonoma 14.8.8 on July 27, 2026. Their security notices list 155, 138 and 127 CVE fixes, respectively, for a combined 420 entries, though some vulnerabilities overlap across releases. Apple’s acknowledgements credit research involving AI tools including Anthropic’s Claude and OpenAI’s Codex, underscoring their growing role in identifying security defects at scale.

Apple Intelligence Prompt-Injection Flaw Exposed With 76% Success Rate2026-04-10 · 2 reports · similarity 0.81

Apple Intelligence is Apple's core service for integrating generative AI into the iPhone, iPad and Mac. Prompt injection uses specially crafted instructions to mislead a model into ignoring its original rules. Researchers said such attacks could bypass content guardrails and induce inappropriate responses, highlighting data and user-safety risks as AI moves onto consumer devices.

A new study disclosed a prompt-injection technique targeting Apple Intelligence that achieved an attack success rate of up to 76% in testing, bypassing Apple's safeguards and manipulating model output. Apple has patched the flaw in newer operating-system releases, including iOS 26.4. The incident involved no financial losses, but experts warned that model updates could create new avenues for bypasses, requiring AI defenses to be tested continuously.

Mark Radar|MARK RADAR

If you search news on Google, you can set Mark Radar as a preferred source—our coverage will show up more often in your results. Set as preferred source on Google →

All times are in Taipei time (GMT+8)