Skip to main content

Claude, Codex, and other AI tools credited in today’s Apple security releases

Apple’s technical details on the many security fixes included in today’s operating system updates show how quickly AI tools are becoming part of vulnerability research. Here are the details.

AI tools credited across Apple’s updates

Earlier today, Apple released:

As soon as the updates were rolled out, Apple updated its security releases page with more information on several of the issues addressed, including the affected components and devices, their potential impact, how Apple fixed them, and the researchers credited with reporting them.

One notable detail in today’s documents is their sheer length, especially considering that Apple released the 26.5.2 updates less than a month ago and said they included fixes originally planned for the 26.6 release cycle.

Another notable detail is that Anthropic researchers and Claude are credited with fixes involving WebKit, WebKit Storage, and WebDAV, some of which were made alongside researchers from Calif.io.

That is the same research team that said in May it had used Anthropic’s Mythos Preview model to help build a working macOS kernel memory corruption exploit on M5 silicon in just five days.

The Calif is credited for several kernel security fixes in every operating system update released today, alongside more than a dozen researchers credited for those vulnerabilities, suggesting that multiple teams independently reported the same underlying issues.

In fact, Apple addressed many other kernel vulnerabilities in this release cycle, with 30 distinct CVEs listed across all of today’s operating system updates.

It is also worth noting that Apple has had access to Claude Mythos Preview through Anthropic’s Project Glasswing since April. As a result, the number of vulnerabilities found internally with Claude could be higher than the public credits suggest.

Finally, Anthropic is not the only AI company represented in today’s notes. Apple also credits work involving OpenAI Codex Security, Z.AI’s GLM, and NVIDIA’s AI Red Team, among others.

While some of those names also appeared in last month’s security notes, today’s updates are further proof of how quickly AI-assisted security research is evolving, and how companies will have to move quickly to adjust their update schedules (and bug bounty programs) to this new reality.

Worth checking out on Amazon

FTC: We use income earning auto affiliate links. More.

You’re reading 9to5Mac — experts who break news about Apple and its surrounding ecosystem, day after day. Be sure to check out our homepage for all the latest news, and follow 9to5Mac on Twitter, Facebook, and LinkedIn to stay in the loop. Don’t know where to start? Check out our exclusive stories, reviews, how-tos, and subscribe to our YouTube channel

Comments

Author

Avatar for Marcus Mendes Marcus Mendes

Marcus Mendes is a Brazilian tech podcaster and journalist who has been closely following Apple since the mid-2000s.

He began covering Apple news in Brazilian media in 2012 and later broadened his focus to the wider tech industry, hosting a daily podcast for seven years.