Apple Intelligence, the personal AI system integrated into newer Macs, iPhones, and other iThings, can be hijacked using prompt injection, forcing the model into producing an attacker-controlled result and putting millions of users at risk, researchers have shown. Apple Intelligence includes an on-device LLM integrated into supported iPhone 15 Pro and later eligible models, iPads and Macs with M1 or later, iPad models with A17 Pro, and Apple Vision Pro. Native Apple apps like Mail, Messages, Notes, Photos, Safari, and Siri use its features, and it's accessible to third-party developers via an API. Security researchers at RSAC estimate there are at least 200 million Apple Intelligence-capable devices in use as of December 2025, and up to 1 million apps on the Apple App Store that employ it. So they decided to try to break in - and the vast majority of the time, it worked. The RSAC team used two techniques to bypass Apple's input and output filters and the safety guardrails on Apple Intelligence's local model. They tested the attack with 100 random prompts and succeeded 76 percent of the time, according to a report shared with The Register ahead of publication. "We knew that we wanted to come up with some sort of prompt that would evade the pre-filtering, the post-filtering, as well as any guardrails within the model itself, so we started probing the model," Petros Efstathopoulos, VP of research and development at RSAC, told us. The researchers disclosed their findings to Apple...
Security reserchers tricked Apple Intelligence into cursing
The Register
·Jessica Lyons
·Published Apr 9, 2026
·Updated
Affected Software
4 affected components
Apple Apple Intelligence (iOS / iPhone 15 Pro and later and eligible models)<26.4
Apple Apple Intelligence (macOS / Macs with M1 or later)<26.4
Apple Apple Intelligence (iPad / iPad models with A17 Pro)
Apple Apple Intelligence (Apple Vision Pro)