Apple released security updates for iPhone, iPad, MacBook, and Safari on June 29, 2026, uncoupled from a major operating system release. The company justified the shift by pointing to the need to respond to the acceleration of AI-powered attacks. It remains unclear whether the policy change is permanent or an initial trial, and Apple has not specified how much more frequent the new patching cycle will be.
- Apple decoupled security updates from the major release cycle, issuing patches on June 29, 2026 (iOS 26.5.2, iPadOS 26.5.2, macOS Tahoe 26.5.2, Safari 26.5.2).
- The official rationale, conveyed via Reuters and reported by Dark Reading, is adaptation to the "reality" of AI as an accelerator of malicious hacking tool development.
- The June 29 patches did not address actively exploited vulnerabilities; their purpose was to establish a faster general cadence.
- CVE-2025-43529 (CVSS 8.8, WebKit use-after-free) and CVE-2026-20700 (CVSS 7.8, memory corruption) both appear in the CISA KEV catalog with confirmed active exploitation, but are not linked to the June 29 patches.
- iVerify discovered roughly a dozen bugs in about two months using AI tools via the OpenAI program, one of which Apple acknowledged as a CVE.
Apple's Statement and Known Limits
Apple stated via Reuters, as reported by Dark Reading, that it "was adapting to the reality that, given AI's ability to accelerate the development of malicious hacking tools, it was necessary to reduce the time between when updates were made public and when they got into customers' hands." The vendor has not quantified the new interval nor disclosed any internal reorganizations to support it.
According to the same source, the patches released on June 29 did not address actively exploited vulnerabilities. They constituted the opening of a new rhythm. Apple has not specified whether the change is definitive or experimental.
Context of Actively Exploited CVEs
During the period in question, two Apple vulnerabilities appear in the CISA Known Exploited Vulnerabilities catalog with confirmed active exploitation. CVE-2025-43529, a use-after-free in the WebKit rendering engine, carries a CVSS 3.1 score of 8.8. Apple stated this vulnerability was exploited in "extremely sophisticated" attacks against specific individuals. CVE-2026-20700, classified as memory corruption, has a CVSS score of 7.8 and received the same operational description from the vendor.
Both entries in the NVD database report CISA KEV status without details on the initial attack vector or the specific campaign. The dossier does not clarify whether these two vulnerabilities were discovered or weaponized using AI tools, nor whether they fall among those identified by the iVerify team. These CVEs were not resolved by the June 29, 2026 patches.
Field Evidence: iVerify and AI-Driven Testing
Rocky Cole, CEO of iVerify, provided empirical verification of the phenomenon Apple described. Through the OpenAI Trusted Access for Cyber program, the iVerify team identified roughly a dozen bugs in about two months using AI tools. One of these was acknowledged by Apple as a CVE.
Cole stated that "in some cases, we were able to use AI tools to see those [vulnerabilities] into exploitation." The original English phrasing — "see those into exploitation" — is ambiguous and does not necessarily equate to full practical exploit realization. The quote does not specify the vulnerability type or the platform affected by the acknowledged CVE.
"In 2018, the average time to exploitation was about 63 days. In the last two years, that number has actually flipped negative, meaning that, on average, attackers are now routinely weaponizing a flaw before a patch is even public. Zero-days are now, on average, being used more than n-days." — Rocky Cole, CEO iVerify, citing Mandiant
The Mandiant data shows a trend reversal: from 2018, when the average time was about 63 days, to negative values in the last two years. The source does not specify whether this calculation covers only Apple vulnerabilities or has a broader scope.
What Changes
Apple's policy shift introduces uncertainty for organizations managing iOS devices. With no clarity on whether the new cadence is permanent or experimental, nor how much more frequent the cycle will be, security teams cannot yet recalibrate processes on a definitive basis.
If confirmed, the higher patch frequency does not alter a known architectural deficit. According to Cole, "iOS is the only widely used computing platform in the world that doesn't have a true security framework on top of it." The absence of a third-party XDR or EDR layer means the device depends solely on the vendor's speed and accuracy.
Cole added: "I think more frequent patching helps, but it doesn't fully close the gap, because there remains a single point of defense with no fallback if something slips through. And against AI-accelerated discovery, something will slip through." This is an analysis from iVerify's CEO, not a statement from Apple.
Sources and Limits
This article relies primarily on a structured editorial source (Dark Reading), which reports Apple statements via Reuters and an interview with Rocky Cole of iVerify. CVE details derive from separate NVD records. It was not possible to independently verify Apple's statements or the Mandiant data cited by Cole. Information on exploitation timelines, the experimental or permanent nature of the change, and the scope of the Mandiant calculation presents specificity limits that cannot be resolved with available sources.
Information has been verified against cited sources and is current as of publication.
Sources
- https://www.darkreading.com/cybersecurity-operations/apple-patch-policy-ai
- https://support.apple.com/en-us/100100
- https://nvd.nist.gov/vuln/detail/CVE-2025-43529
- https://nvd.nist.gov/vuln/detail/CVE-2026-20700
- https://nvd.nist.gov/vuln
- https://nvd.nist.gov/vuln/search
- https://nvd.nist.gov/vuln/categories
- https://nvd.nist.gov/vuln/data-feeds
- https://nvd.nist.gov/vuln/vendor-comments