Source status: Apple's July 27 security-content pages directly name researchers using Claude or working with Claude and Anthropic Research on all three CVEs.
Summary
Appleās July release notes add three direct Claude-assisted credits:
- CVE-2026-64703, a WebDAV use-after-free with denial-of-service impact.
- CVE-2026-64704, an SMB type-confusion issue.
- CVE-2026-64757, WebKit memory corruption reachable through web content.
The same fixes appear across several Apple product pages but each CVE remains one unique site-wide identifier.
References
- Apple: macOS Tahoe 26.6 security content
- Apple: iOS and iPadOS 26.6 security content
- Apple: tvOS 26.6 security content
Catalogued in the Bugflation public ledger. Disagree with the attribution or severity label? Email the desk.