What it is
This profile covers vulnerability discoveries where a primary vendor or upstream advisory explicitly names a Z.AI GLM model. It does not infer AI use from a researcher’s employer or team name.
What is verified
FreeBSD advisories directly credit GLM on eight CVEs involving ptrace, thread
state, jails, unlinkat(), kernel TLS, and ZFS. Apple’s June 29, 2026 security
release separately credits researchers “Using GLM From Z.AI” on a WebKit
memory-handling vulnerability.
Several FreeBSD records have additional finders. Bugflation therefore records GLM participation without claiming that every issue was found exclusively by the model or one operator.
Why it matters
The record spans both memory-safety and logic vulnerabilities in mature operating-system and browser code. It is also unusually strong evidence: attribution comes from the affected vendors rather than only from the model developer.