All findings

CVE-2026-43715 high

Apple credits Claude on WebKit use-after-free

Apple directly credits Milad Nasr and Nicholas Carlini working with Claude and Anthropic on a WebKit use-after-free that can cause memory corruption.

Bug class
Use-after-free and browser memory corruption
Affected codebase
Apple WebKit
Credited system
Claude / Anthropic Research
Disclosed
June 29, 2026
Attribution
Direct source attribution
Severity
high
Source status: Apple's June 29 advisory directly credits Milad Nasr and Nicholas Carlini with Claude, Anthropic, on CVE-2026-43715.

Summary

CVE-2026-43715 is a use-after-free in WebKit. Processing malicious web content may lead to memory corruption. Apple addressed the flaw with improved memory management.

Attribution

The Apple reporter line names both the human researchers and Claude, making this direct affected-vendor attribution.


References


Catalogued in the Bugflation public ledger. Disagree with the attribution or severity label? Email the desk.