AI has become Apple’s latest bug detective
Artificial intelligence is becoming a force multiplier for Apple security research. Apple’s latest 26.5.2 software update includes patches for a record number of bugs — many of them identified by security researchers using AI-assisted tools.
A record haul of fixes
The numbers tell the story. Apple fixed 87 security vulnerabilities in iOS and iPadOS 26.6, along with an additional 155 patches for Macs. Roughly 100 flaws have been patched in each of Apple’s other operating systems: watchOS, tvOS, and visionOS. Taken together, these represent record numbers for an Apple security update.
This is only the beginning. The scale of the release echoes the impact AI coding agents are already having on security research and may well reflect Apple’s Project Glasswing research with Anthropic and others to use AI to identify software vulnerabilities.
Apple’s use of AI for security research is visible in the official release note. Read through it and you’ll see multiple credits to Claude, Codex, and AI adjacent tools, labs, and researchers. These tools identified flaws across Apple’s systems, including in WebKit, WebDAV, and WebKit Storage.
For good and ill
It’s a neat illustration of the sea change under way as AI adoption accelerates. This release highlights how security researchers are leaning into AI tools to check platform security just as heavily as attackers are. One fix in today’s release is credited to researchers from Calif.io, who some may recall used Anthropic’s Mythos Preview model to create a working macOS kernel memory corruption exploit in just a few days.
The release is proof positive that while AI can be used to identify vulnerabilities to undermine protection, it can also be used to identify opportunities to further secure the platforms. It is also true that as AI use across the security industry grows, the number of flaws identified will also accelerate; it’s doubtful we’ll ever reach a point at which there are no flaws at all. Apple is likely to beef up its own internal observability tools following the acquisition of SigLens, which might help it identify even more bugs using AI.
Don’t delay, install today
None of these matters much, though, if the security patches never get installed — and the delay between security patch release and installation represents a huge opportunity for attackers. Recent analysis from Fleet Device Management found that 79% of organizations take more than a day to deploy critical security patches, even as attackers increasingly exploit vulnerabilities within hours of disclosure. The same report also showed something else to worry about: AI tools are spreading fast across the enterprise, often without the version control or auditability that would let anyone track how they’re actually being used.
Despite their number, the tally of fixes Apple has published isn’t the end of the story. In this case, while Apple has published its latest fixes, how many of those vulnerabilities have already been abused in the weeks between discovery and security patch release? More to the point, how swiftly will Apple’s installed base update devices now, and how many attackers will use that delay to dive in and do the damage?
It’s a security arms race
Adam Boynton, senior security strategy manager at Jamf noted that one vulnerability, CVE-2026-43810, can be exploited by a remote user to corrupt kernel memory. “The WebKit fixes are easy to read as a phishing story, when they are actually something slightly different,” he said.
“The raw material for targeted spyware is browser engine memory corruption, and those chains are expensive enough that they get pointed at specific people like senior executives, journalists, anyone whose access justifies the cost. That’s the honest reason to update promptly rather than eventually.
“In other words, this update matters less for its raw numbers than for what those numbers represent: an arms race between defenders and attackers who are both, increasingly, running the same kind of tools,” Boynton said.
You can follow me on social media! Join me on BlueSky, LinkedIn, Mastodon and subscribe to The Core.ComputerworldRead More