Topics / topic

Apple

1 item across 1 edition. First seen Wed 16 Sep, last seen Wed 16 Sep.

Wednesday, 16 September 2026

Apple ships record 260+ CVE patch cycle; ten fixes credit AI bug-hunters, most of them Claude with Anthropic Research beneficialSingle source

  • The Register reports Apple "addressed more than 260 CVEs across all of its operating systems, browsers, and other software products, marking the largest single patch cycle in Cupertino's history". iOS 27 and macOS 27 Golden Gate, released Monday, address "a record 122 and 204 security vulnerabilities, respectively".
  • "Of these hundreds of CVEs, however, there are only ten (by our count) that AI is directly credited with finding", The Register writes. Two are in iOS 27: CVE-2026-65410, in iPhone and iPad AVE video encoders, credited to the AI bug-finding firm Calif "along with Claude and Anthropic Research"; and CVE-2026-65409, a type-confusion issue in the Foundation framework, credited to Calif's Bruce Dang "in collaboration with Claude and Anthropic Research".
  • macOS 27 credits AI helpers with eight more, including CVE-2026-43692 and CVE-2026-64790 in CUPS — the first a validation issue a remote user can exploit to execute malicious code — both credited to Aaron Grattafiori and the Nvidia AI Red Team; CVE-2026-43690 and CVE-2026-43719 in SMB, and CVE-2026-65374, CVE-2026-65375 and CVE-2026-43677 in WebDAV, all credited to Dang with Claude and Anthropic.
  • This is a count by The Register's own reading of Apple's advisories, not a figure Apple published. The Register says none of the vulnerabilities is listed as being under active exploitation. Ten out of more than 260 is the measured share of this cycle attributable to AI-assisted discovery, on that counting.