All findings

CVE-2026-43663 high

Apple credits researchers using Z.AI GLM on WebKit CVE

Apple's June security release explicitly says researchers used GLM from Z.AI while reporting a WebKit memory-handling vulnerability.

Bug class
WebKit memory-handling failure and browser crash
Affected codebase
Apple WebKit
Credited system
Z.AI GLM
Disclosed
June 29, 2026
Attribution
Direct source attribution
Severity
high
Source status: Apple directly includes the phrase 'Using GLM From Z.AI' in the CVE-2026-43663 reporter line alongside the participating researchers.

Summary

CVE-2026-43663 is a WebKit memory-handling flaw that can cause an unexpected process crash when malicious web content is processed. Apple fixed it with improved memory handling.

Attribution

The vendor itself explicitly identifies GLM use. The entry does not assign the finding exclusively to one researcher because Apple’s credit line names multiple participants.


References


Catalogued in the Bugflation public ledger. Disagree with the attribution or severity label? Email the desk.