Skip to content
Rush Commerce
Software & Dev3 min read

Apple's 29 CVEs: nine found by OpenAI Codex

Apple shipped its third security release in three weeks. Nine of the 29 CVEs are credited to OpenAI Codex Security. Your patch cadence is the thing that broke.

Apple shipped macOS Tahoe 26.6.2, iOS and iPadOS 26.6.1, and iOS and iPadOS 18.7.10 on August 17. Twenty-nine CVEs. That is Apple's third security release in three weeks. The detail worth your attention is not the count — it is that nine of the 29 are credited to OpenAI Codex Security, and one more came from Meta's Red Team X.

What actually happened

Per MacRumors, the release fixes 29 vulnerabilities. Twenty-one are WebKit. Nine carry an OpenAI Codex Security credit.

The one to act on is CVE-2026-65346, an integer overflow in ImageIO — the framework nearly every Apple app uses to read image files. The Register reports it was found by Nik Tsytsarkin of Meta's Red Team X, and that processing a malicious image could produce arbitrary code execution. Apple fixed it with improved input validation. Nothing in this batch is known to be exploited, but image parsing bugs are the classic delivery path for zero-click spyware, so the window between patch and proof-of-concept is short. Also in the set: CVE-2026-65329, a Telephony authentication flaw that allows traffic interception from a privileged network position.

Why AI-found CVEs matter for your patch cadence

The supply of findings just went up, permanently. Nine credited findings from one AI security program in one release is not a stunt. Fuzzing and code review scaled to machine throughput produce more real bugs per month than a quarterly patch window was ever designed to absorb. We saw the same shape when agents surfaced Redis zero-days and when GLM-5.3 reported 2,436 vulnerabilities across 269 open-source projects.

Three releases in three weeks breaks a monthly ritual. If your process is "we patch Macs at the end of the month," you now spend most of every month behind. The fix is not heroics, it is automation: enable automatic security updates on staff devices, and keep a short list of machines you deliberately hold back for compatibility. Two tiers, documented.

Zero known exploitation is a schedule, not a verdict. Apple did not confirm exploitation for CVE-2026-65346. Attackers read the same advisory you do, and a patch is a specification for the bug it fixes. Treat "not yet exploited" as your head start, not your excuse.

Check versions, not badges. Run sw_vers and confirm 26.6.2 on Macs. On phones, the number to see is 26.6.1, or 18.7.10 on older hardware. A device showing "Update Available" for three weeks is an unpatched device.

Key takeaways

  • Apple released macOS Tahoe 26.6.2, iOS/iPadOS 26.6.1 and iOS/iPadOS 18.7.10 on August 17, 2026, fixing 29 CVEs
  • Twenty-one are WebKit; nine are credited to OpenAI Codex Security
  • CVE-2026-65346 is an ImageIO integer overflow reported by Meta's Red Team X that can yield code execution from a malicious image
  • CVE-2026-65329 is a Telephony authentication flaw permitting traffic interception from a privileged network position
  • None in this batch are known to be exploited, but image parsing flaws are a standard zero-click spyware delivery path
  • This is Apple's third security release in three weeks — turn on automatic security updates and verify with sw_vers rather than trusting the update badge

AI is finding bugs faster than most teams patch. We set up device update policy, version reporting, and a documented hold-back list, so you can answer "is every machine current?" in one query instead of one afternoon. Ask us to sort out your patch cadence or see how we build systems you can inspect.

Sources: MacRumors, The Register.

  • #apple
  • #cve-2026-65346
  • #patch-management
  • #ai-security
  • #endpoint-security
TR

Tommy Rush — Founder, Rush Commerce

Operator turned builder. 15+ years running operations — now shipping the systems businesses run on. More

Get The Rush Report weekly — one email, zero fluff.