All findings

CVE-2026-28972, CVE-2026-28986 medium

Apple credits Xint Code on two May 2026 kernel CVEs

Apple's May 2026 advisories credit Ryan Hileman via Xint Code on two kernel vulnerabilities involving unexpected system termination and kernel-state leakage.

Bug class
Kernel race condition and information leakage
Affected codebase
Apple kernel
Credited system
Xint Code
Disclosed
May 11, 2026
Attribution
Direct source attribution
Severity
medium
Source status: Apple's May 2026 advisories directly credit Ryan Hileman via Xint Code (xint.io) on CVE-2026-28972 and CVE-2026-28986. Both records have additional reporters; this entry counts the public Xint Code participation.

Summary

Apple’s May 2026 security pages credit Ryan Hileman via Xint Code on two kernel issues:

Attribution

This is direct vendor attribution. Apple names Xint Code in the reporter line, and the existing Xint Code model profile supplies the AI-assisted system context for Bugflation.


References


Catalogued in the Bugflation public ledger. Disagree with the attribution or severity label? Email the desk.