All findings

CVE-2026-43707, CVE-2026-43716, CVE-2026-43745 high

Apple credits Codex Security on three June 2026 WebKit CVEs

Apple's June 29 security release directly names OpenAI Codex Security on three WebKit memory-safety vulnerabilities, including one explicit out-of-bounds write.

Bug class
Memory corruption, memory-handling crash, and out-of-bounds write
Affected codebase
Apple WebKit
Credited system
OpenAI Aardvark / Codex Security
Disclosed
June 29, 2026
Attribution
Direct source attribution
Severity
high
Source status: Apple directly names OpenAI Codex Security on all three reporter lines. The same CVEs appear across Apple platform notes and are counted once each.

Summary

Apple describes CVE-2026-43707 as memory corruption that can cause a process crash. CVE-2026-43716 is a Safari-crash issue addressed through improved memory handling, without a more specific public bug class. CVE-2026-43745 is an out-of-bounds write that can crash Safari.

The type-confusion and out-of-bounds-access descriptions adjacent to these credits in Apple’s advisory belong to CVE-2026-43705 and CVE-2026-43676, respectively, and are not assigned to the Codex-reported issues here.

Attribution

This is direct vendor attribution. Apple names OpenAI Codex Security in each reporter line, so no inference from researcher affiliation is required.


References


Catalogued in the Bugflation public ledger. Disagree with the attribution or severity label? Email the desk.