Apple Ships Three Dozen Fixes, Including WebKit Bugs Surfaced by LLM-Assisted Review
Four of the patched WebKit flaws were found with help from Claude and Codex, a quiet data point on how vendors are folding AI into vulnerability discovery.

Key points
- Apple released security updates Monday for iOS, iPadOS, macOS and Safari, patching more than 30 flaws.
- Four WebKit vulnerabilities were discovered using AI tools, specifically Anthropic's Claude and OpenAI's Codex Security.
- One of the four, CVE-2026-43707, is a memory corruption flaw triggerable by maliciously crafted web content.
- No in-the-wild exploitation has been disclosed for any bug in this batch.
- The disclosure norm is shifting: Apple naming AI tools in release notes signals that LLM-assisted analysis is becoming routine at platform vendors.
What did Apple actually patch?
Apple pushed security updates Monday covering iOS, iPadOS, macOS and Safari, closing more than 30 flaws. The notable detail isn't the volume. It's the provenance of four WebKit bugs.
According to Apple's release notes, the company credits AI-assisted analysis, specifically Anthropic's Claude and OpenAI's Codex Security tooling, with surfacing several memory corruption issues patched in WebKit. One of those, tracked as CVE-2026-43707, is a memory corruption flaw that could be triggered by processing maliciously crafted web content.
WebKit is a perennial soft target. The engine sits behind Safari on every Apple device and has historically been the path mercenary spyware vendors use to land on iPhones. Pre-auth memory corruption in WebKit draws attention from offensive research shops whether commercial or state-aligned.
Should you worry about active exploitation?
No in-the-wild exploitation has been disclosed for this batch. Apple's advisories don't carry the "may have been actively exploited" language the company reserves for known zero-days. That distinction matters. A patched WebKit bug doesn't automatically mean Intellexa or NSO had it first.
IOS, iPadOS, macOS Sequoia, macOS Sonoma and Safari all received updates. Managed fleets should prioritize the WebKit fixes given the engine's exposure to drive-by attacks and any embedded WKWebView component in third-party apps. Those embedded views are easy to forget in patch posture reviews.
What does AI-assisted discovery actually mean here?
Vendors running large language model tooling against their own codebases isn't new. Google's Big Sleep project flagged a SQLite flaw last year, and Microsoft has been public about similar efforts. What's shifting is the disclosure norm. Apple naming Claude and Codex in release notes is a signal that AI-assisted variant analysis is moving from research curiosity to a routine part of the software development lifecycle at platform vendors.
The timing connects to a pattern we've been tracking. Our 25 June story on the Gaslight macOS stealer documented an implant that shipped with an embedded prompt-injection payload aimed specifically at LLM-assisted reverse engineering tools, and a day later we reported on North Korean malware engineered to redirect AI analyzers. Defenders adopting AI discovery and adversaries actively subverting it are developments happening in parallel, not sequence.
The broader question for threat intel teams is whether the offensive side is running comparable tooling at comparable scale. Reasonable assumption: yes. Several commercial spyware vendors and at least one suspected state-aligned cluster have advertised for ML engineers with vulnerability research backgrounds over the past year. That's not confirmation of operational use, and I'd treat any claim that APTs are "weaponizing LLMs to find zero-days" with skepticism absent telemetry.
What we can say with medium confidence is that the discovery asymmetry is narrowing on both sides. Defenders are catching variants faster. Attackers, probably, are too. The more telling development here is Apple's willingness to say so in public release notes.
Apple's full advisory list is available on its security releases page.



