Apple to Overhaul macOS Full Disk Access Controls as AI Agents Gain More System Power
Apple says it will require a far more deliberate approval step before granting apps Full Disk Access on macOS, warning that the permission's sweeping reach becomes more dangerous...
Apple Patches CoreGraphics Zero-Day Used in Spyware-Style Attacks on iPhones and iPads
Apple's iOS 26.7.1 and iPadOS 26.7.1 updates close CVE-2026-86950, an out-of-bounds write in CoreGraphics that attackers used in what Apple describes as an extremely sophisticated attack against specifically...
Apple’s Largest Coordinated Update Closes 273 Unique Vulnerabilities
Apple has issued coordinated updates across its device ecosystem addressing 273 unique CVEs. The fixes cover remote code execution, kernel privilege escalation, authentication bypass, privacy failures and web-content...
Legacy VNC Login on macOS Screen Sharing Could Hand Attackers a Root Shell
Researchers found that macOS's Screen Sharing service kept its file-transfer helpers running as root even when a session was authenticated with nothing more than a shared VNC password....
PamStealer: New macOS Infostealer Disguises Itself as the Maccy Clipboard Manager
PamStealer is a newly discovered macOS infostealer that impersonates the Maccy clipboard manager, using a two-stage AppleScript-to-Rust infection chain to steal Keychain data, browser credentials, and clipboard contents...
Apple’s Unpatched ‘Hide My Email’ Flaw Has Exposed User Identities for Over a Year
An unpatched vulnerability in Apple's Hide My Email feature can expose users' real email addresses behind their iCloud+ anonymization aliases, researcher Tyler Murphy and 404 Media have confirmed....
World Leaks Ransomware Dumps 630 GB of Tata Electronics Data — Confidential Apple and Tesla Files Exposed
Ransomware group World Leaks has published 630+ GB of stolen Tata Electronics data including confidential Apple iPhone manufacturing specs and Tesla engineering drawings marked as trade secrets. Tata...
usbliter8: New iPhone BootROM Vulnerability Exposes A12/A13 Apple SoCs to Full Chain-of-Trust Compromise
Security researchers have disclosed 'usbliter8,' a critical hardware-level BootROM vulnerability affecting Apple devices with A12, S4/S5, and A13 SoCs. The flaw allows attackers to bypass Apple's entire Secure...