Apple is significantly increasing the frequency and volume of its security updates, driven by the rapid advancements in AI tools used by both bug hunters and malicious actors. The company released a record number of fixes in its recent iOS 26.6, iPadOS 26.6, and macOS Tahoe 26.6 updates, including 87 vulnerabilities in iOS/iPadOS and 155 for Macs. This accelerated patching pace is a direct response to the heightened threat from AI-assisted attacks, which can quickly turn discovered flaws into exploitable vulnerabilities.
Several AI models, including Anthropic's Claude, OpenAI's Codex Security, NVIDIA AI Red Team, and Z.ai's GLM model, were credited with discovering bugs in Apple's software. Notably, Claude, through Project Glasswing, identified CVE-2026-64757, a significant vulnerability in the WebKit engine that could lead to browser crashes and user data leaks on Apple Vision Pro. This marks a departure from Apple's usual practice, as the company explicitly credited AI models by name, highlighting the growing role of AI in security testing.
Apple's decision to release updates like iOS 26.5.2 ahead of its typical schedule underscores the urgency. This update, which included over 25 fixes (15 for WebKit), was pushed out early because AI can rapidly create exploits once a vulnerability is known. This shift represents a significant change in Apple's long-standing practice of bundling security fixes with broader software releases, indicating that the company views the AI-accelerated threat as a structural problem. The company has also stated there's no evidence these specific patched vulnerabilities were exploited before the fix was available.
The constant discovery of new vulnerabilities, often aided by AI, has created an "arms race" between defenders and attackers. Experts like Adam Boynton from Jamf emphasize that these record-breaking updates reflect this ongoing battle. While AI is helping Apple and other companies find and patch bugs, the same technology can enable attackers to discover and exploit flaws more quickly, making timely updates crucial for users. For instance, one critical bug (CVE-2026-43810) could allow a remote user to corrupt kernel memory, necessitating prompt installation of updates to mitigate risks from targeted spyware attacks.