All findings

CVE-2026-43722 + 3 more high

Apple directly credits ThreatBook XGPT across four system CVEs

Apple names researchers using ThreatBook XGPT on four kernel, SMB, and Libnotify vulnerabilities disclosed in June and July 2026.

Bug class
Kernel state disclosure and use-after-free, SMB remote denial of service, and Libnotify out-of-bounds write
Affected codebase
Apple kernel, SMB, and Libnotify
Credited system
ThreatBook XGPT
Disclosed
July 27, 2026
Attribution
Direct source attribution
Severity
high
Source status: Apple's June 29 and July 27 security-content pages directly name researchers using XGPT. The four exact CVEs are counted; component-only additional recognition without an issue identifier is excluded.

Summary

The XGPT-attributed set comprises kernel state disclosure, a kernel use-after- free, an SMB flaw permitting a remote crash, and a Libnotify out-of-bounds write. Apple supplies both the accepted-fix trail and the direct AI-system credit.


References


Catalogued in the Bugflation public ledger. Disagree with the attribution or severity label? Email the desk.