{"id":1513,"date":"2026-06-30T07:30:15","date_gmt":"2026-06-30T07:30:15","guid":{"rendered":"https:\/\/thedigitalfortress.us\/?p=1513"},"modified":"2026-06-30T07:30:15","modified_gmt":"2026-06-30T07:30:15","slug":"apple-patches-30-ios-macos-safari-flaws-including-ai-discovered-webkit-bugs","status":"publish","type":"post","link":"https:\/\/thedigitalfortress.us\/?p=1513","title":{"rendered":"Apple Patches 30+ iOS, macOS, Safari Flaws, Including AI-Discovered WebKit Bugs"},"content":{"rendered":"<div>\n<p><span class=\"p-author\"><i class=\"icon-font icon-user\">\ue804<\/i><span class=\"author\">Ravie Lakshmanan<\/span><i class=\"icon-font icon-calendar\">\ue802<\/i><span class=\"author\">Jun 30, 2026<\/span><\/span><span class=\"p-tags\">Artificial Intelligence \/ Vulnerability<\/span><\/p>\n<\/div>\n<div id=\"articlebody\">\n<div class=\"separator\" style=\"clear: both;\"><a href=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEjgEWbrJH-z_uAL6GFaOqplYF1ewSOBvFpaKD24W74VEBaSO-pW3sy0I0e57Bmc9yBKV4vb6zWYaVjd-oTSy2sSQNSubgQHcmFav_bp3HnySXcSGR-ocRiUfYcXgUXm44XZyrdNnIq2JqJxZQG5bnbui12eVoG3GPgVnGy9AE6vfDp3km5TTtf6rjPv6FZV\/s1700-e365\/apple-updates-ai.jpg\" style=\"display: block;  text-align: center; clear: left; float: left;\"><\/a><\/div>\n<p>Apple on Monday <a href=\"https:\/\/support.apple.com\/en-us\/100100\">released<\/a> security updates for iOS, macOS, and the Safari web browser to address over three dozen flaws, including four vulnerabilities in WebKit that were discovered using artificial intelligence (AI) tools like Anthropic Claude and OpenAI Codex Security.<\/p>\n<p>The WebKit vulnerabilities are listed below &#8211;<\/p>\n<ul>\n<li><b>CVE-2026-43707<\/b> &#8211; A memory corruption issue that could result in an unexpected process crash when processing maliciously crafted web content. It was addressed with improved memory handling.<\/li>\n<li><b>CVE-2026-43716<\/b> &#8211; An unspecified issue that could result in an unexpected Safari crash when processing maliciously crafted web content. It was addressed with improved memory handling.<\/li>\n<li><b>CVE-2026-43745<\/b> &#8211; An out-of-bounds write issue that could result in an unexpected Safari crash when processing maliciously crafted web content. It was addressed with improved input validation.<\/li>\n<li><b>CVE-2026-43715<\/b> &#8211; A use-after-free issue that could result in memory corruption when processing maliciously crafted web content. It was addressed with improved memory management.<\/li>\n<\/ul>\n<p>The first three security defects have been credited by Apple to OpenAI Codex Security, while Anthropic researchers Milad Nasr and Nicholas Carlini, along with Claude, have been acknowledged for CVE-2026-43715.<\/p>\n<p>The four vulnerabilities are part of nearly 30 vulnerabilities that have been patched in WebKit, an open-source web browser engine developed by Apple. Others include a use-after-free issue in WebKit Canvas (CVE-2026-43720) and a vulnerability that could be exploited by a malicious website to process restricted web content outside the sandbox (CVE-2026-43725).<\/p>\n<div class=\"dog_two clear\">\n<div class=\"cf\"><a href=\"https:\/\/thehackernews.uk\/ai-cant-stop-d\" rel=\"nofollow noopener sponsored\" target=\"_blank\"><img loading=\"lazy\" decoding=\"async\" class=\"lazyload\" alt=\"Cybersecurity\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEjPEV6-530TOlxG6PjrmdlY623wpBwduZ7t1HV6flcmO5R4q4AmfixDUzW0CrhlvMVNWbhvOIso-UDNTka4W_W9Chrdj_dglwBZwi7DuePM2IMIl-hfUYVIqBXgfpr_2619K8Gptb4LzwJ6gUbi7lWl2M8AFQJsHEaw63Q7tZ6708YGruiHrr0Y2W9YYxLQ\/s728-e100\/ThreatLocker-d.png\" width=\"729\" height=\"91\"\/><\/a><\/div>\n<\/div>\n<p>Apple has also remediated three bugs that could be exploited by a malicious app to leak sensitive kernel state (CVE-2026-43722), cause unexpected system termination or write kernel memory (CVE-2026-43724), or corrupt kernel memory (CVE-2026-39868). Security researcher Hyunwoo Kim, who discovered Dirty Frag, has been credited with discovering and reporting CVE-2026-43724 and CVE-2026-43722.<\/p>\n<p>The updates are available for <a href=\"https:\/\/support.apple.com\/en-us\/127594\">iOS 26.5.2, iPadOS 26.5.2<\/a>, <a href=\"https:\/\/support.apple.com\/en-us\/127595\">macOS Tahoe 26.5.2<\/a>, and <a href=\"https:\/\/support.apple.com\/en-us\/127685\">Safari 26.5.2<\/a>. None of the patched vulnerabilities has been disclosed as actively exploited in the wild.<\/p>\n<p>In a statement <a href=\"https:\/\/www.reuters.com\/business\/apple-says-it-is-releasing-updates-early-response-ai-cybersecurity-concerns-2026-06-29\/\">shared<\/a> with Reuters, Apple said it&#8217;s making the security updates much earlier than before in response to concerns that AI tools could accelerate the development of exploits and act as an enabler of cyber warfare, shrinking the window between discovery and weaponization to hours.<\/p>\n<p>The company said \u00abit was adapting to \u200bthe reality that, given the ability of artificial intelligence \u200bto speed the development of malicious hacking tools, it \u2060needed to reduce the time between when updates were first \u200bmade public and when they were put into customers&#8217; hands,\u00bb Reuters reported.<\/p>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>\ue804Ravie Lakshmanan\ue802Jun 30, 2026Artificial Intelligence \/ Vulnerability Apple on Monday released security updates for iOS, macOS, and the Safari web browser to address over three dozen flaws, including four vulnerabilities&hellip;<\/p>\n","protected":false},"author":1,"featured_media":1514,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[2247,618,809,11,584,428,421,57,2246,621],"class_list":["post-1513","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-aidiscovered","tag-apple","tag-bugs","tag-flaws","tag-including","tag-ios","tag-macos","tag-patches","tag-safari","tag-webkit"],"_links":{"self":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts\/1513","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=1513"}],"version-history":[{"count":0,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts\/1513\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/media\/1514"}],"wp:attachment":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=1513"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=1513"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=1513"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}