Apple patches record 260+ bugs, AI credited with just 10

Apple patches record 260+ bugs, AI credited with just 10

Apple's newest operating system updates, iOS 27 and macOS 27 Golden Gate, released on Monday, together with fixes across its other operating systems, browsers and software, address more than 260 CVEs in total. The Register calls it the largest single patch cycle in Apple's history, while noting the total is unremarkable next to Microsoft's 974 bugs disclosed earlier the same month. iOS 27 alone fixes a record 122 vulnerabilities, and macOS 27 Golden Gate fixes a record 204.

Of those 260-plus fixes, only 10 are credited to AI, by The Register's own count rather than any tally Apple has published. Just two of iOS 27's 122 CVEs name an AI assistant: CVE-2026-65410, a bug in iPhone and iPad AVE video encoders that can cause unexpected system termination, and CVE-2026-65409, a type-confusion issue in iOS's Foundation framework that can be abused to cause a denial of service. Both are credited to AI-bug-hunting firm Calif working with Anthropic's Claude and Anthropic Research; the second also names Calif researcher Bruce Dang as the human collaborator. macOS 27 fixes both of those plus eight more the article groups under AI-assisted finds, among them a validation flaw in the CUPS printing system (CVE-2026-43692) that could let a remote attacker terminate the app or run malicious code, credited to Aaron Grattafiori and Nvidia's AI Red Team, and a use-after-free bug in the SMB network protocol (CVE-2026-43719) that Apple's advisory says can crash an affected Mac when a malicious network share is mounted, credited to Dang, fellow researcher Jakob Pammer, Claude and Anthropic.

Not every serious bug in the update carries an AI credit. A privilege-escalation flaw that could let an app gain root access (CVE-2026-43689) is credited to Nosebeard Labs researchers Andreas Jaegersberger and Ro Achterberg, and a Background Assets logic flaw that could expose sensitive user data (CVE-2026-65406) is credited solely to Baidu Security's Ye Zhang; neither credit line mentions AI.

The wider point the article draws is about where AI security tools stand right now: they are getting much faster and better at finding vulnerabilities, but AI has not become similarly good at writing the patches to fix what it finds. None of the more than 260 patched vulnerabilities are listed as under active exploitation, which the piece treats as the one upside for anyone updating now, though it also warns that attackers are already looking to exploit the newly disclosed bugs, using AI tools of their own.

Key facts

  • Apple's newest security updates address more than 260 CVEs across all its operating systems, browsers and other software, the largest single patch cycle in the company's history, though the total is unremarkable next to Microsoft's 974 bugs disclosed earlier the same month.
  • iOS 27 fixes a record 122 vulnerabilities and macOS 27 Golden Gate fixes a record 204, both released Monday.
  • Of the 260-plus patched flaws, only 10 are credited to AI, by The Register's own count rather than an Apple-published tally: just 2 of iOS 27's 122, plus 8 more found only in macOS 27.
  • Anthropic's Claude and Anthropic Research are named alongside Calif researcher Bruce Dang on several of the AI-credited bugs, including a use-after-free SMB flaw (CVE-2026-43719); a CUPS flaw that could allow remote code execution (CVE-2026-43692) is credited instead to Aaron Grattafiori and Nvidia's AI Red Team.
  • None of the 260-plus patched vulnerabilities are listed as under active exploitation, and the article notes AI has gotten much faster at finding security bugs without getting similarly good at writing the patches for them.

Why it matters

A single Apple patch cycle fixing more than 260 CVEs, a company record, says as much about the size of Apple's attack surface as it does about how security research is changing. AI-assisted bug hunting gets a real, named credit line here (Claude and Anthropic Research alongside human researchers), not just industry talk, though it still accounts for only 10 of the 260-plus fixes. The article's other point matters just as much: the same AI models that are getting fast at finding flaws have not yet gotten good at fixing them, so bug discovery and bug remediation are moving at very different speeds.

Who it affects

Anyone running iOS 27, macOS 27 Golden Gate, or Apple's other patched operating systems, browsers and software; security and IT teams that track Apple's CVEs for patch management; and the researchers and firms named in the credit lines, including Calif, Nvidia's AI Red Team, Nosebeard Labs and Baidu Security, whose disclosure work is what the count is built from. Anthropic is drawn in too: Claude and Anthropic Research appear by name in Apple's own CVE credits, not just in marketing.

How to use it

There is nothing to buy or sign up for here, only an update to install. Apple device owners should update to iOS 27 or macOS 27 Golden Gate: the cycle closes off a remote-code-execution path in CUPS, several SMB and WebDAV bugs, and a root-privilege-escalation flaw, even though Apple has not flagged any of them as already exploited. Anyone who wants technical detail on a specific CVE should go to Apple's own advisory pages; this piece is a summary of the public credit lines, not a substitute for them.

How solid is it

The reporting is built from Apple's own published CVE credit listings plus one quoted advisory line, under a named byline (Jessica Lyons, Cybersecurity Editor), and the AI-bug-hunting angle is real, not a joke, despite The Register's usual irreverent headline. One caveat worth carrying over: the ten-bug AI-credited tally is the outlet's own count, not a figure Apple published, and it is not all the same kind of credit. Several bugs, including the SMB and WebDAV flaws, explicitly name Claude and Anthropic Research as co-finders; the CUPS and StorageKit flaws instead credit only Nvidia's AI Red Team by name, a security team, not a specific AI model.

Risks and caveats

No CVSS severity scores are given for any of the 260-plus flaws, so this piece alone will not tell you how dangerous each one is relative to the others. No exact calendar release date is given for iOS 27 or macOS 27 Golden Gate, only Monday. How Claude and Anthropic Research actually found their credited bugs is not explained beyond the credit line itself. And while none of the vulnerabilities are listed as under active exploitation yet, the article cautions that could change quickly as attackers move to exploit the newly disclosed bugs, warning that they are using AI to do it too.

“Mounting a maliciously crafted SMB network share may lead to system termination”

— Apple, security advisory for CVE-2026-43719