Source status: Apple confirms the accepted CVE and credits XBreach.ai, while XBreach's own platform material establishes the autonomous AI workflow. The upstream credit names the organization rather than a specific system, so attribution remains self-reported.
Summary
CVE-2026-39875 is a CUPS privilege-boundary flaw that could allow an attacker to obtain root privileges. This is a shared public vendor credit, not a claim of exclusive XBreach discovery.
References
Catalogued in the Bugflation public ledger. Disagree with the attribution or severity label? Email the desk.