Apple Intelligence flaw kept stolen tokens reusable on another device
ID: 13c3beba-9463-5cc3-84b2-9ac17e5ee609
STIX ID: report--13c3beba-9463-5cc3-84b2-9ac17e5ee609
Feed Name: Help Net Security
Threat Score
Researchers discovered that Apple Intelligence on macOS 26 stored device authorization tokens (TGTs and OTTs) in the login keychain in plaintext, enabling the 'Serpent' attack: malware can prompt for keychain access, exfiltrate tokens, and allow an attacker to impersonate victims or exhaust their AIquotas; Apple assigned CVE-2025-43509 and partially mitigated the issue in macOS 26.2 by moving tokens to the iCloud keychain, though researchers demonstrated possible bypasses.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
