Summary
Apple describes CVE-2026-43707 as memory corruption that can cause a process crash. CVE-2026-43716 is a Safari-crash issue addressed through improved memory handling, without a more specific public bug class. CVE-2026-43745 is an out-of-bounds write that can crash Safari.
The type-confusion and out-of-bounds-access descriptions adjacent to these credits in Appleās advisory belong to CVE-2026-43705 and CVE-2026-43676, respectively, and are not assigned to the Codex-reported issues here.
Attribution
This is direct vendor attribution. Apple names OpenAI Codex Security in each reporter line, so no inference from researcher affiliation is required.
References
Catalogued in the Bugflation public ledger. Disagree with the attribution or severity label? Email the desk.