logo

Security researchers tricked Apple Intelligence into cursing at users. It could have been a lot worse

ID: d77cd154-cb4c-5352-ae28-8e7bdd969586

STIX ID: report--d77cd154-cb4c-5352-ae28-8e7bdd969586

Feed Name: The Register (Security)

Threat Score
60/100

Date Published: 2026-04-09

Date Updated: 2026-04-26

Author: Jessica Lyons

...
...

Researchers at RSAC demonstrated a prompt-injection technique (Neural Exec combined with a Unicode right-to-left override) that reliably bypassed Apple Intelligence's filters on many devices, producing attacker-controlled outputs and able to manipulate local data (e.g., creating contacts). The team tested 100 prompts with a 76% success rate; the issue was disclosed to Apple on October 15, 2025 and Apple reportedly mitigated the specific attack in iOS/macOS 26.4, though prompt-injection remains a broader, ongoing risk.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.