It's also worth pointing out that the developers at Mozilla literally decided to make a brand new programming language (Rust) that eliminated an entire categories of bugs and started working on a new browser (Servo) where its components could be switched into firefox.
Then Mozilla fired the team working on it.
Lesson 1: Better tools and processes eliminate bugs.
Lesson 2: If you don't have the tools, make them.
Lesson 3: Mismanagement leads to security vulnerabilities.
Yes, and even after introducing and using Rust, there were still vulns in the remaining code.
FWIW, Rust is my main language, so I am grateful to the humans that created it, and it is indeed a monumental effort. But vuln finding is a different kind of creative endeavour, and one that is heavily weighted against defenders.
You would choose rust (from a security standpoint) because it massively reduces memory safety issues (which from a Microsoft study was responsible for around 70% of bugs).
Then you look at things like linting, fuzzing, design by contract, proofing, deterministic test runs, etc...
Yes, I should have been clear - I don't mind AI working on patches or vuln-hunting; my issue with MacOS 27 is the amount of AI included in the OS that is not opt-in. I use Claude Code everyday - but it doesn't run locally on my main production machines.
If Apple wanted to make the OS more secure, they would make the OS more modular, allowing users to reduce the surface risk by not installing bloated components
You have the same long list for Sequoia 15.8, so how is that better? Besides, newer OSes are also more likely to have uniquely knew bugs from both AI slop and in general all the shiny new broken features