TLDRocket
Sign in

Apple Fixes WebKit Flaws in iOS and macOS, With Help From AI Tools

Security Affairs

Apple patched a bunch of WebKit bugs in iOS, iPadOS, macOS and Safari — four of them found using AI tools like Claude and Codex. Apple's also shipping fixes outside its usual release cycle now, because AI is speeding up how fast attackers can weaponize known flaws.

Based on reporting by Security Affairs — read the original for the full story.

Summary, retelling and take written by AI under human oversight; images are AI-generated illustrations. How we work · Report an error

Apple's latest round of security updates landed Monday, and the interesting part isn't the bug count. It's who found some of them. Four WebKit vulnerabilities in this patch batch, including a couple of nasty memory corruption issues and a use-after-free flaw, were discovered with help from AI tools: Anthropic's Claude and OpenAI's Codex. That's a notable line to see in a security advisory, and it signals a shift in who's doing the grunt work of vulnerability hunting.

The fixes themselves cover close to 30 issues in WebKit, the rendering engine behind Safari and basically every in-app browser view on Apple's platforms. Among them: a use-after-free bug in WebKit Canvas, a sandbox-escape flaw that could let a malicious site pull data it shouldn't have access to, and three kernel-level bugs that could leak system state, crash a device, or corrupt kernel memory outright. Researcher Hyunwoo Kim, who previously uncovered the Dirty Frag exploit, is credited with finding two of those kernel bugs. Apple says none of this was exploited in the wild before the patch shipped, which is good news, though hardly a reason to sit on the update.

What's genuinely new here is the timing. Apple typically folds security fixes into its next scheduled iOS release, waiting for the usual developer and tester cycle to run its course before pushing updates broadly. This time it didn't wait. iOS 26.5.2, iPadOS 26.5.2, macOS Tahoe 26.5.2, and Safari 26.5.2 all shipped ahead of the planned 26.6 release, and Apple told Reuters the reason explicitly: AI is compressing the gap between when a flaw becomes known and when someone can turn it into a working exploit. Reuters called it a departure from Apple's longstanding practice of bundling fixes into major releases, and that phrasing matters. This isn't Apple reacting to a single incident. It's Apple adjusting its whole cadence because the threat model changed.

The irony writes itself. The same class of AI tools that helped Apple's security team spot these WebKit bugs before anyone else could abuse them are, in other hands, shortening the runway attackers need to find and exploit similar flaws. Apple isn't pretending otherwise. The company is effectively acknowledging that the old release rhythm, built around months-long beta cycles, no longer matches how quickly a disclosed bug can become a live attack. Most of these particular bugs just crash things on their own, but crash bugs get chained together, and that's usually how the serious damage happens.

My take — AI-written commentary, not fact-checked reporting

I run a site about AI news, so forgive me for finding it almost funny that Apple is now racing the very technology it's using to defend itself. This is the honest shape of the next few years: AI tools compress both the offense and defense timelines simultaneously, and whoever patches faster wins that round. Apple breaking its own release cadence to ship out-of-band fixes isn't overreaction, it's the correct read of the room, and other vendors clinging to quarterly patch schedules should take note.

Read more about this at: Security Affairs

Related stories

The daily briefing

Every AI story that matters, in your inbox by 8am.

TLDRocket reads all relevant sources, removes duplicate coverage, and summarises the day in two minutes. Follow companies and topics for alerts, or get the briefing in Slack. Free, no spam, unsubscribe anytime.