← All news

vulnerability

Apple drops bundled patches as AI shrinks exploit window

2026-07-03

Apple has quietly changed the way it ships security fixes. For years it preferred to stuff patches inside major operating system releases, which left users waiting weeks or months for a fix to actually land on their device. On 29 June it did something different: a round of security updates for iPhone, iPad, MacBook and Safari, with no glossy new OS attached. Asked why, Apple told Reuters what most defenders already suspected. AI is speeding up how quickly attackers turn a disclosed flaw into a working exploit, and the gap between the two has to shrink.

The numbers make the case on Apple's behalf. Mandiant's time-to-exploit research shows the average has fallen from around 63 days in 2018 to negative territory across the last two years. In plain English, attackers are routinely weaponising bugs before a patch is even public. Zero-days are now used more often than n-days.

AI on the offensive side of the ledger

Rocky Cole, CEO of iVerify, told Reuters his two-person team has already turned up roughly a dozen bugs using models made available through OpenAI's Trusted Access for Cyber program. One of them has been acknowledged by Apple as a CVE, and the team has taken some of the others through to working exploits. If two people with model access can move at that pace, it is not hard to picture what a well-funded offensive group is doing with the same tools.

That reframes the patch calendar. Bundling a security fix with a shiny redesign like Liquid Glass made sense when the exploit window was measured in weeks. It makes less sense when it can be measured in days, or in the wrong direction.

The install problem

Faster patches only help if people actually apply them. Cole recounts a Coruna infection last week on a device still running iOS 16. The user had stopped tapping update because they did not like the look of the newer interface. That is the quiet cost of tying security to design changes users did not ask for. Once someone gets burned by an unfamiliar UI, they learn to leave the update prompt alone.

Enterprises have their own version of the same problem. Most run an N-1 strategy on OS versions to avoid compatibility headaches, which builds a delay into the rollout by design. It is a sensible operational choice that happens to be a gift to anyone racing a patch.

The bit Apple has not conceded

Cole's sharper point is structural. iOS remains the only widely used platform without a real security framework that third parties can build on. No EDR. No XDR. No hooks for the tools enterprise defenders lean on everywhere else in their estate. Apple's pitch on device security has always been a version of trust us, we've got this.

A quicker patch cadence is a useful concession, and worth acknowledging. It is not the same as letting defenders help.

Apple drops bundled patches as AI shrinks exploit window | RiskSense