Source status: Apple directly includes the phrase 'Using GLM From Z.AI' in the CVE-2026-43663 reporter line alongside the participating researchers.
Summary
CVE-2026-43663 is a WebKit memory-handling flaw that can cause an unexpected process crash when malicious web content is processed. Apple fixed it with improved memory handling.
Attribution
The vendor itself explicitly identifies GLM use. The entry does not assign the finding exclusively to one researcher because Appleās credit line names multiple participants.
References
Catalogued in the Bugflation public ledger. Disagree with the attribution or severity label? Email the desk.