Apple is increasingly relying on AI companies to strengthen the security of its operating systems. In the latest iOS, iPadOS, watchOS, tvOS, visionOS, and macOS Tahoe system updates, the official has fixed a large number of security vulnerabilities, and a significant portion of these fixes are attributed to AI-assisted security research — this is the first time Apple has directly mentioned the name of an AI model in its official CVE vulnerability attribution list.
According to Apple's official security announcement, the Claude model from Anthropic and the Codex Security from OpenAI each helped identify three vulnerabilities, while NVIDIA's AI red team contributed two, and Z.ai's GLM model also successfully assisted in fixing one. Among them, security researchers Milad Nasr and Nicholas Carlini used the Claude model to help fix security vulnerabilities in key modules such as WebKit, WebKit Storage, and WebDAV.
Glasswing Initiative Shows Promising Results, 100 Million Dollars to Build an AI Security Alliance
Apple's deep application of AI security research is partly due to Anthropic's "Glasswing Initiative" launched in April this year. The initiative cost 100 million dollars and involves tech giants such as Apple, Microsoft, Google, Amazon AWS, and NVIDIA. By obtaining the exclusive "Claude Mythos Preview" model from Anthropic in advance, they can discover and fix vulnerabilities before potential attackers exploit them.
The core value of this model lies in allowing AI models to play a "preliminary warning" role in cybersecurity, rather than waiting until vulnerabilities are exploited by hackers before taking action. Just as Microsoft announced last week that it would significantly increase the use of AI in the security development of Windows 11, Apple's latest list of acknowledged vulnerabilities marks that industry leaders are upgrading AI from a supporting tool to a core force in security governance. When AI can both find and fix vulnerabilities, the balance of cyber warfare is quietly shifting.
