2026-06-06 is live. RBL, certificate, and uptime monitoring — now in public beta.

News

Apple fixes 30+ flaws across iOS, macOS and Safari, including AI-discovered WebKit bugs


Apple rolled out security patches for iOS, macOS and the Safari browser that remediate upwards of three dozen security weaknesses. Among the fixes are four WebKit vulnerabilities that were identified with assistance from artificial intelligence systems, including Anthropic’s Claude and OpenAI’s Codex Security.

The WebKit issues attributed to AI-assisted research include CVE-2026-43707, a memory-corruption flaw that could lead to an unexpected process termination when a browser processed specially crafted web content; Apple says it addressed this by improving how memory is handled. CVE-2026-43716 covers an unspecified bug that could crash Safari when malicious web content is encountered and was also mitigated via enhanced memory handling. CVE-2026-43745 is an out-of-bounds write that might trigger an unexpected Safari crash; Apple fixed this by adding stricter input validation. Finally, CVE-2026-43715 is a use-after-free vulnerability that could cause memory corruption while processing crafted web data; Apple resolved it with improved memory management.

Apple credits OpenAI Codex Security for reporting the first three of those defects, while Anthropic researchers Milad Nasr and Nicholas Carlini – working with Claude – are acknowledged for discovering CVE-2026-43715.

Those four flaws are part of nearly 30 separate WebKit vulnerabilities covered in this update. Other WebKit fixes include a use-after-free in the WebKit Canvas subsystem (CVE-2026-43720) and a bug that could allow a malicious website to access restricted content outside the browser sandbox (CVE-2026-43725).

In addition to browser engine fixes, Apple patched three kernel-level issues that could be abused by a malicious application: CVE-2026-43722 could allow leakage of sensitive kernel state, CVE-2026-43724 could cause unexpected system termination or permit writing to kernel memory, and CVE-2026-39868 could result in kernel memory corruption. Security researcher Hyunwoo Kim – the investigator behind the Dirty Frag finding – is credited with reporting CVE-2026-43724 and CVE-2026-43722.

The security updates are available as iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2, and Safari 26.5.2. Apple reports that none of the patched vulnerabilities have been publicly disclosed as being actively exploited in the wild.

Explaining the accelerated release schedule, Apple told Reuters it is moving to deliver fixes more quickly because AI tools can dramatically speed up the creation of exploit code, shrinking the interval between discovery and weaponization to hours. The company said it is adjusting its processes to reduce the time between when an update is announced and when customers actually receive it, given the growing risk posed by AI-enabled exploit development.

First published on June 30, 2026.
Last updated on July 15, 2026.