logo

Apple Intelligence flaw kept stolen tokens reusable on another device

ID: 13c3beba-9463-5cc3-84b2-9ac17e5ee609

STIX ID: report--13c3beba-9463-5cc3-84b2-9ac17e5ee609

Feed Name: Help Net Security

Threat Score
70/100

Date Published: 2026-04-22

Date Updated: 2026-04-28

Author: Sinisa Markovic

...
...

Researchers discovered that Apple Intelligence on macOS 26 stored device authorization tokens (TGTs and OTTs) in the login keychain in plaintext, enabling the 'Serpent' attack: malware can prompt for keychain access, exfiltrate tokens, and allow an attacker to impersonate victims or exhaust their AIquotas; Apple assigned CVE-2025-43509 and partially mitigated the issue in macOS 26.2 by moving tokens to the iCloud keychain, though researchers demonstrated possible bypasses.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.