All findings

CVE-2026-64703, CVE-2026-64704, CVE-2026-64757 high

Apple's July security wave directly credits Claude on three memory-safety CVEs

Apple credits Claude-assisted researchers on SMB, WebDAV, and WebKit memory-safety issues across its July 27 platform releases.

Bug class
Type confusion, use-after-free, and browser memory corruption
Affected codebase
Apple SMB, WebDAV, and WebKit
Credited system
Claude / Anthropic Research
Disclosed
July 27, 2026
Attribution
Direct source attribution
Severity
high
Source status: Apple's July 27 security-content pages directly name researchers using Claude or working with Claude and Anthropic Research on all three CVEs.

Summary

Apple’s July release notes add three direct Claude-assisted credits:

The same fixes appear across several Apple product pages but each CVE remains one unique site-wide identifier.


References


Catalogued in the Bugflation public ledger. Disagree with the attribution or severity label? Email the desk.