Source status: Apple's June 29 and July 27 security-content pages directly name researchers using XGPT. The four exact CVEs are counted; component-only additional recognition without an issue identifier is excluded.
Summary
The XGPT-attributed set comprises kernel state disclosure, a kernel use-after- free, an SMB flaw permitting a remote crash, and a Libnotify out-of-bounds write. Apple supplies both the accepted-fix trail and the direct AI-system credit.
References
- Apple: June 29 security content
- Apple: macOS Tahoe 26.6 security content
- Apple: iOS and iPadOS 26.6 security content
Catalogued in the Bugflation public ledger. Disagree with the attribution or severity label? Email the desk.