Source status: Apple's May 2026 advisories directly credit Ryan Hileman via Xint Code (xint.io) on CVE-2026-28972 and CVE-2026-28986. Both records have additional reporters; this entry counts the public Xint Code participation.
Summary
Appleās May 2026 security pages credit Ryan Hileman via Xint Code on two kernel issues:
- CVE-2026-28972, a race condition where an app may be able to cause unexpected system termination.
- CVE-2026-28986, a logging issue where an app may be able to leak sensitive kernel state.
Attribution
This is direct vendor attribution. Apple names Xint Code in the reporter line, and the existing Xint Code model profile supplies the AI-assisted system context for Bugflation.
References
Catalogued in the Bugflation public ledger. Disagree with the attribution or severity label? Email the desk.