upvote
Those were voluntary disclosures by two Anthropic researchers and the security firm Calif. I know one more CVE on the list that was discovered using an AI agent and wasn't disclosed as such. I suspect there are many more.
reply
Apple isn’t friends with OpenAI anymore
reply
What happened?
reply
The gist is, OpenAI hired a high ranking Apple employee who helped other Apple employees get hired by OpenAI and exfiltrate Apple trade secrets in the process.

Allegedly of course.

reply
> high ranking Apple employee

Jony Ive basically works for Open AI (it's more complicated, but it's a good approximation), and has more or less rebuilt a designing team over there.

He's not the central person mentioned in Apple's accusations but that's arguably the central point that's triggering all of this.

reply
Didn't he live Apple a very long time ago?
reply
Yes, the high ranking employee at the center of the accusations is not Ive, but Tang Tan, former VP of product design

https://www.bbc.com/news/articles/cy8w379e091o

reply
He left in 2019 and formed his own company, that did design work for Apple until 2022.

He "took" several Apple employees with him when he left and there's been a steady stream of Apple employees going to OpenAI.

Ive isn’t responsible for all of them obviously, but the articles about lawsuits says there are 400 former Apple employees at OpenAI.

reply
Sounds like Apple needs to do a better job at being a place where employees want to stay.
reply
Or, good that the craze for ever thinner laptops has been slowed?
reply
A lot more than several. Sounded like it ended up being a large chunk of his team.
reply
> Lots of "in collaboration with Claude and Anthropic Research" mentions

I wouldn't say 4 is lots. The entire list is massive. I haven't counted myself, but someone claimed that macOS 26.6 has the all-time record with 155 CVEs.

reply
Considering that in Feb 2026 (https://support.apple.com/en-us/126348) Claude wasn't mentioned even once, 4 sure sounds like "lots" compared to nothing :) But you're right, it's subjective ultimately.
reply
Apple also hosts a copy of Claude internally in their servers.
reply
Do they? As in Claude but on premises? Wonder if this is gonna be the solution that e.g. banks will require, exactly like they do now for cloud services (e.g. Azure on premises).
reply
Banks are all about security theatre so probably not.
reply
Pretty extreme solution… you can get Claude models from AWS Bedrock and Google Model Zoo. These are both very helpful for compliance and security, but do require you to have a cloud strategy.
reply
Some data is so sensitive it likely has to stay on premises though.
reply
That's why banks use Azure on Premises (not sure if other providers offer the same, but the investment bank I worked at did)
reply
Yeah, albeit an increasingly second-rate experience, at least when it comes to Bedrock.
reply
source?

edit: it seems asking for a source it frowned uppon in this site. And it seems there's no source.

reply
I don't believe it's published anywhere, but it's common knowledge to Apple engineers. I can second the poster's assertion that they run Claude internally.
reply
I know they use it, they host it too?

That would be a very Apple thing to do.

reply
Yes, they host it on their own infrastructure.
reply
Makes sense. I’m sure they have no interest in every Claude prompt going to Anthropic to keep eyes on what Apple is up to.
reply
Yeah that's why I asked. It would be one thing to use, another to host.

And it seems nobody has a source so it's just humors as usual.

reply
> That would be a very Apple thing to do.

That's something Steve Jobs would have done.

reply
I don’t know about hosting it internally but a an Apple focused podcast I listen to (Accidental Tech Podcast) has mentioned numerous times in the last few months they’re using Claude heavily. And they know Apple insiders.
reply
also “ Using GLM From Z.AI”
reply