'Xint Code' Reports 2 Cases Including CVSS 9.8 Kernel Vulnerability
Theori, an offensive cybersecurity specialist company, announced that it has discovered security vulnerabilities in Apple's operating systems through its AI-based source code security analysis solution and has led to the application of official security patches.
On the 5th, Theori announced that two vulnerabilities discovered by its AI source code security analysis solution 'Xint Code' in Apple's major operating systems have been reflected in Apple's recently published security updates.
The most noteworthy vulnerability addressed this time is the kernel vulnerability 'CVE-2026-64775,' which is evaluated as Critical with a CVSS (Common Vulnerability Scoring System) score of 9.8.
According to Theori, this vulnerability is a flaw that allows a specific application to abnormally terminate the system without requiring separate user interaction. Apple explained that it has fixed problems occurring in the memory initialization process and improved memory handling methods to block related risks.
The concurrently fixed 'CVE-2026-64744' is a vulnerability at the CVSS 5.5 level, known as an issue where a specific application can expose kernel memory information. Apple resolved this by applying additional validation procedures.
This security update has been applied across major Apple platforms including △iOS 26.6 △iPadOS 26.6 △macOS Tahoe 26.6 △macOS Sequoia 15.7.8 △macOS Sonoma 14.8.8 △tvOS 26.6 △visionOS 26.6 △watchOS 26.6.
Theori evaluated this Apple vulnerability discovery as another case demonstrating the scope of application for AI-based source code vulnerability detection technology.
The company previously disclosed that it had discovered the Linux kernel privilege escalation vulnerability 'Copy Fail (CVE-2026-31431)' and three high-risk Android vulnerabilities (CVE-2026-0095, CVE-2026-0138, CVE-2026-0143).
'Xint,' developed by Theori, is an AI-based security platform providing source code analysis, penetration testing, and security validation capabilities.
Among these, 'Xint Code' is introduced as a white-box security analysis solution that detects potential vulnerabilities by analyzing the structure and data flow of source code.
Kwak Kyung-joo, Head of Theori's Xint Product Division, stated, "This case demonstrates that the AI engine can discover security vulnerabilities that are difficult for humans to find even in large-scale source code environments."
















