Wednesday, July 29, 2026

News

Apple Patches Record 87 iOS, 155 macOS Bugs, Some Found by AI

HardwarePatryk Raba

Apple released iOS 26.6 and macOS Tahoe 26.6 on July 27 with a record number of security fixes. Some vulnerabilities, including a Safari bug, were found by AI systems including Anthropic's Claude, which Apple explicitly credited in its acknowledgments.

Contents
  1. What Claude found
  2. Four AI companies in one update
  3. Project Glasswing in the background
  4. An arms race
  5. What this means for users

Apple released iOS 26.6, iPadOS 26.6, and macOS Tahoe 26.6 on July 27, 2026, patching more security vulnerabilities than any single update round in the company's history. Some of the bugs, including a serious issue in the Safari browser, were found by artificial intelligence systems, and for the first time Apple credited a specific AI model by name this explicitly.

What Claude found

The key AI-assisted discovery is CVE-2026-64757, a bug in the WebKit engine responsible for rendering pages in Safari and any app that displays web content. A specially crafted webpage could crash the browser, and on the Apple Vision Pro the issue also allowed user data to leak. The flaw was reported by two Anthropic researchers, Milad Nasr and Nicholas Carlini, who used the Claude model to find it.

In the official iOS 26.6 security content notes, Apple described the discoverers directly as "Milad Nasr and Nicholas Carlini with Claude, Anthropic." That marks a departure from the company's usual practice of crediting only individuals and organizations in its acknowledgments, without naming the tools they used.

Four AI companies in one update

Anthropic isn't the only AI lab named in the security notes for July's update round. Claude and OpenAI's Codex Security were each credited with three reported vulnerabilities, the NVIDIA AI Red Team accounted for two, and the GLM model from China's Z.ai for one. That shows bug-hunting by language models has stopped being a single company's experiment and become a regular part of Apple's software testing process.

Beyond the AI-found issues, the update also includes serious fixes discovered through traditional methods, among them a flaw allowing remote kernel memory corruption without prior physical access to the device, and an integer overflow bug in the ImageIO library that could have enabled arbitrary code execution when processing a maliciously crafted image.

Project Glasswing in the background

Anthropic's involvement in finding Apple's vulnerabilities traces back to Project Glasswing, launched in April 2026, through which the company gave selected partners access to an unreleased model, Claude Mythos Preview, to scan critical infrastructure for security bugs. Apple, AWS, Broadcom, Cisco, CrowdStrike, Google, Microsoft, NVIDIA, and Palo Alto Networks were among those granted access to the model, and Anthropic committed $100 million in compute credits plus $4 million for open source organizations to the program.

The model had already demonstrated how effective it can be in this role, finding among other things a remote OpenBSD vulnerability that had gone undetected for 27 years and an FFmpeg library bug overlooked for 16 years. Anthropic itself has publicly warned that its model can be excessively effective at finding exploits, raising questions about controlling tools capable of discovering vulnerabilities faster than companies can patch them.

An arms race

The accelerated patching pace isn't a coincidence. A month earlier, after releasing iOS 26.5.2 with more than 25 fixes, including 15 for WebKit, Apple announced it would ship security updates faster than its previous scheduled cycle, explicitly citing the growing threat from AI-assisted attacks. According to data cited in analyses of this trend, as many as 79 percent of organizations need more than a day to deploy critical fixes, while attackers can exploit a disclosed vulnerability within hours of a patch's release.

Browser engine memory corruption is the raw material for targeted spyware, and these attack chains are expensive enough that they're aimed at specific individuals, such as company executives or journalists - Adam Boynton, senior enterprise strategy manager, Jamf
WebKit bugs should worry users because they can be exploited, for example, by phishing kits - Daniel Card, cybersecurity consultant, Xservus Limited

What this means for users

Apple stresses that none of the vulnerabilities patched on July 27 had previously been exploited in attacks, but experts quoted around the update warn the situation changes quickly once bug details become public. According to mobile security specialists, once a vulnerability is documented it stops being costly to exploit and quickly ends up in the hands of attackers who previously wouldn't have had the budget for it.

For the average iPhone or Mac user, the practical takeaway is simple: install the update as soon as possible via Settings, then General and Software Update, rather than waiting for the next system reminder. For businesses and IT administrators, the event signals that AI models are becoming a permanent part of the vulnerability lifecycle, on both the defender and potential attacker side, and patching speed needs to keep pace with how fast bugs are now being found.

Share: