AI Tool Uncovers Critical Apple OS Flaws, Forces Emergency Patch
August 5, 2026
A South Korean offensive cybersecurity firm, Theori, revealed that its AI-based white-box testing tool Xint Code found two critical Apple OS vulnerabilities, prompting an emergency patch from Apple.
The fixes include CVE-2026-64775, a high-severity kernel vulnerability exploitable without user interaction via a zero-click method (CVSS 9.8), and CVE-2026-64744, a kernel memory data-leak vulnerability (CVSS 5.5).
Theori also runs αprism, a large language model security solution, and Dreamhack, a cybersecurity education platform with a substantial user base.
Xint Code has a track record of uncovering critical flaws, including CVE-2026-31431 (Copy Fail) in the Linux kernel and several high-risk Android vulnerabilities later patched by Google.
Theori stresses the practical value of Xint Code, capable of identifying blind spots in millions of lines of source code and delivering tangible proof-of-concept exploits.
Affected Apple OS versions include iOS 26.6, iPadOS 26.6, macOS Tahoe 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, tvOS 26.6, visionOS 26.6, and watchOS 26.6.
The Xint platform comprises Xint Code (white-box), Xint Web (black-box), and Xint Pulse (on-demand), with Theori advising major clients like Google, Microsoft, Okta, and Samsung Electronics.
Kwak Kyung-joo, head of Theori’s Xint Product Division, states that Xint Code enables rapid, accurate vulnerability discovery across Linux, Android, and Apple’s iOS/macOS ecosystems.
CVE-2026-64775 originated during memory initialization and was mitigated by overhauling memory handling, while CVE-2026-64744 was addressed by introducing validation logic to block the data-leak pathway at its source.
Summary based on 1 source
Get a daily email with more Tech stories
Source

BigGo Finance • Aug 5, 2026
South Korean Security Firm Theori Discovers Critical Apple OS Vulnerabilities, Prompting Emergency Patch