Apple Intelligence flaw kept stolen tokens reusable on another device

Apple claims that Apple Intelligence, a GenAI service provided on its operating systems, is designed with an extra focus on user security and privacy through a two-stage authentication and authorization system using anonymous access tokens. However, researchers from The Ohio State University have identified vulnerabilities in this design, demonstrated on macOS 26.0 (Tahoe), that allow attackers to steal and reuse these tokens. Service infrastructure The system offloads complex requests to cloud servers using Private Cloud … More

The post Apple Intelligence flaw kept stolen tokens reusable on another device appeared first on Help Net Security.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top