Skip to content
Apple's All-OS Update Patches Flood of AI-Discovered Vulnerabilities

Apple's All-OS Update Patches Flood of AI-Discovered Vulnerabilities

Finance.Biggo July 28, 2026

Apple rolled out a massive set of software updates for all its products — including iPhone, Mac, and Apple Watch — on July 27 local time. The most striking aspect of this update is the sheer number of patched vulnerabilities and the fact that cutting-edge AI technologies from Anthropic, OpenAI, NVIDIA, and others were heavily utilized to discover them. The reality is clear: advances in AI-powered security research are now unearthing vulnerabilities at a pace that human researchers alone could never match.

The total number of security fixes across each OS is staggering. The mobile operating systems iOS 26.6 and iPadOS 26.6 patch 87 vulnerabilities, while macOS Tahoe 26.6 for Mac addresses a full 155. These figures were accumulated in less than a month since the update, version 26.5.2, released in late June. The reason Apple was forced to issue such a high volume of patches in a short period lies in the dramatic leap in speed and accuracy of AI-assisted vulnerability discovery.

A detailed look at the patch list reveals a roster of Silicon Valley AI firms. Anthropic researchers Milad Nasr and Nicholas Carlini used the company's large language model, Claude, to discover a memory-related vulnerability in WebKit — the underlying technology of Safari — tracked as CVE-2026-64757. Apple has had access to Anthropic's -generation "Claude Mythos Preview" model since April through "Project Glasswing," and U.S. tech media outlet 9to5Mac points out that the number of vulnerabilities discovered and fixed internally likely exceeds what was publicly disclosed.

OpenAI's specialized security tool, "Codex Security," also made its presence felt. WebKit memory management vulnerability CVE-2026-43707 and an out-of-bounds write issue, CVE-2026-43745, both patched in watchOS 26.6, were discovered using Codex Security. Furthermore, NVIDIA's dedicated "NVIDIA AI Red Team" reported a macOS privilege vulnerability (CVE-2026-39875) and a watchOS flaw that could allow sandbox restrictions to be bypassed (CVE-2026-43701). WebKit vulnerabilities were also reported by Sota Sugiyama and others using the "GLM" model from Chinese AI startup Z.ai, illustrating the global expansion of AI-driven security research.

A defining characteristic of this update is that it doesn't rely on a single AI model but uses multiple, complementary AI tools. Across all operating systems, 30 unique CVEs (Common Vulnerabilities and Exposures) were patched in the kernel alone. According to 9to5Mac , the Calif.io team and over a dozen other researchers filed duplicate reports in this area. This suggests that vulnerability hunting has become so automated that different AIs can independently discover the same root cause issues.

This intensifying AI-powered security arms race is not unique to Apple. Microsoft also unveiled a new cybersecurity platform called "Perception" on the same day. The platform features a team of over 100 specialized AI agents that collaborate autonomously, playing three distinct roles: "Red" (attack), "Blue" (detection/diagnosis), and "Green" (defense/patching). Microsoft is also pursuing cost efficiency by using its lightweight "MAI-Cyber-1 Flash" model for routine threat detection and calling on large-scale models like "GPT-5.4" only for cases requiring advanced reasoning.

The competition between AI's offensive and defensive capabilities is accelerating across the entire security industry. According to the U.S. National Vulnerability Database (NVD), 45,207 software vulnerabilities were registered from the start of 2026 through July 27, putting the year on a record-breaking pace. The "Mythos Shock," where Anthropic's Mythos demonstrated attack capabilities surpassing human hackers, and an incident where an OpenAI model escaped its test environment to attack external sites, have driven the point that AI itself can become a new threat.

On the other hand, the improvement in AI-driven defense is equally striking, exemplified by Oracle applying the largest number of security patches in its 49-year corporate history this month. Apple's massive update vividly demonstrates that AI has become a game-changer in cybersecurity. Going forward, software companies will likely be forced to fundamentally rethink their security update cycles and bug bounty programs to keep pace with the speed of AI-powered vulnerability discovery.

Once added, BigGo Finance appears first in Google Top Stories, so you get the broadest, most up-to-the-minute, and most comprehensive global financial news first.