Apple’s Bug Credits Now Name OpenAI Codex, Claude and Two More AI Tools

Apple iPhone 18 Pro Photos app Apple Reference Image
Image: Apple

Apple’s own security acknowledgement lines name “OpenAI Codex Security – Amy Burnett” on at least 13 separate WebKit CVEs across two documents posted August 17, 2026. The same two documents also credit “Milad Nasr, Nicholas Carlini with Claude (Anthropic)”, “Artem Dinaburg (Trail of Bits) via Anthropic”, “Using GLM (Z.AI)” and “Aaron Grattafiori (NVIDIA AI Red Team)” on individual WebKit fixes.

Apple iPhone 18 Pro 2up
Apple's iPhone. Safari and WebKit, the component named across these credit lines, run on every current iPhone. Image: Apple

That is four named AI tools or labs appearing in Apple’s own credit lines in a single patch cycle. Apple has not commented on it anywhere in its newsroom, press materials or developer documentation. The only public record of any of this is in the credit lines themselves.

Key facts on these credit lines

ItemWhat Apple’s documents show
Documentshttps://support.apple.com/en-us/148287 (iOS 18.7.10) and https://support.apple.com/en-us/148282 (iOS 26.6.1), both dated August 17, 2026
ComponentAlmost entirely WebKit
Named AI tools or labs in the creditsOpenAI Codex Security, Claude (Anthropic), Anthropic, GLM (Z.AI), NVIDIA AI Red Team
OpenAI Codex Security CVE countAt least 13 separate WebKit CVEs
Apple statement addressing these creditsNone published
Apple iPhone Duo colors
iPhone Duo. Its Safari browser uses the same WebKit engine referenced in Apple's credit lines. Image: Apple

The credit lines, exactly as Apple published them

Apple’s credit lineWhere it appears
“OpenAI Codex Security – Amy Burnett”At least 13 WebKit CVEs, including CVE-2026-65338, 65334, 65331, 65335, 65332, 65333, 65337, 64780, and shared credit on 64784 and 43745
“Milad Nasr, Nicholas Carlini with Claude (Anthropic)”CVE-2026-64757, WebKit
“Artem Dinaburg (Trail of Bits) via Anthropic”CVE-2026-28984, WebKit
“Using GLM (Z.AI)”Listed among the credits for CVE-2026-43663, WebKit
“Aaron Grattafiori (NVIDIA AI Red Team)”CVE-2026-43701, WebKit

Apple’s impact line for CVE-2026-43701 reads: a malicious website may be able to process restricted web content outside the sandbox. That is the extent of the technical description Apple published for that entry. For the OpenAI Codex Security credits, Apple’s documents attach the same short WebKit impact wording used across most of the release, typically describing a Safari crash or memory corruption triggered by crafted web content, without singling out how each fix differed from the next.

Don’t miss the best of The Mac Observer

Set us as a preferred source and our Apple reporting ranks higher in your Google Search results and Discover feed — one tap, no account changes.

Or get it by email

The CVE-2026-64784 and CVE-2026-43745 entries are listed as shared credits, meaning Apple’s document names OpenAI Codex Security alongside at least one other researcher or team on the same line, rather than as the sole credit. Apple’s format for shared credit is the same one it uses everywhere else on the page: names separated by commas, with no indication of which contributor found what.

Both documents predate Apple’s September 9 product event by three weeks. Apple’s press materials from that event make no reference to either document or to any of the credits inside them.

Apple Watch Series 12 2up
Apple Watch, shown for illustration. The credit lines in this article concern WebKit, not watchOS. Image: Apple

Where else an AI name turns up in the same documents

The same two documents also credit “Anonymous (TrendAI Zero Day Initiative)” and “Hossein Lotfi (TrendAI Zero Day Initiative)”, a research program that now carries “AI” in its own name, and “Meta Red Team X – Nik Tsytsarkin” on multiple separate entries. Both credit lines appear exactly as printed here, alongside individually named researchers on the rest of the list.

What Apple has and has not said

  • Apple has published the credit lines themselves, attached to specific CVE numbers, in the two support documents linked above.
  • Apple has not issued a press release, blog post or newsroom statement about any of these four AI tools or labs appearing in its acknowledgements.
  • Apple has not stated how a credited finding was produced, submitted or reviewed.
  • Apple has not grouped these credits separately from its other researcher acknowledgements; they sit in the same list, in the same format, as every other name on the page.

Where this fits against Apple’s other August documents

Both documents landed on the same day as macOS Tahoe 26.6.2 and visionOS 26.6.1 on Apple’s security index, and one day before Safari 26.6.1. Apple’s current phones, iPhone 18 Pro and iPhone Duo, ship with iOS 27 rather than either release named above, and neither device has yet appeared on a security document carrying these credit lines.

What Apple has not said

Apple has not commented publicly, in any channel this article can cite, on the appearance of OpenAI Codex Security, Claude, Anthropic, GLM or NVIDIA AI Red Team in its own acknowledgements. It has not said whether it expects more such credits on future releases.

As of Saturday, September 12, 2026, no newer Apple security document has added to or amended either of the two credit lists cited here, and the next scheduled entry on Apple’s software calendar is iOS 27 on Monday, September 14.