All findings

CVE-2026-64783 high

Apple directly credits Z.AI GLM on a WebKit use-after-free

Apple's July 27 security notes name a researcher using GLM from Z.AI on CVE-2026-64783, a WebKit use-after-free.

Bug class
WebKit use-after-free
Affected codebase
Apple WebKit
Credited system
Z.AI GLM
Disclosed
July 27, 2026
Attribution
Direct source attribution
Severity
high
Source status: Apple directly says the report used GLM from Z.AI. The credit is shared with other researchers; Bugflation does not infer that every credited organization used AI.

Summary

CVE-2026-64783 is a WebKit use-after-free that could lead to a crash when processing malicious web content. Apple names GLM from Z.AI in the accepted reporter credit, making this a direct attribution entry.


References


Catalogued in the Bugflation public ledger. Disagree with the attribution or severity label? Email the desk.