Technology
Is Apple Intelligence on your iPhone really secure?
NEWYou can now listen to Fox News articles!
Apple has spent years telling us that privacy starts on the device. For many users, that message feels reassuring. Your messages, photos, emails and app data sit in your hand, protected by Face ID, passcodes and Apple’s security layers. Now, new research gives Apple’s on-device AI a reality check.
Researchers with RSAC Research found a way to manipulate Apple Intelligence using prompt injection, adversarial prompts and Unicode tricks. In 100 tests, they reported a 76% success rate against the on-device model used by Apple Intelligence. The researchers disclosed the findings to Apple on October 15, 2025. Apple later hardened protections in iOS 26.4 and macOS 26.4, according to RSAC.
Here’s the part that should get your attention: this kind of attack may not require someone to steal your iPhone, crack your passcode or break into Apple’s servers. It could start with carefully crafted text that tricks the AI into doing something you never asked it to do. If your phone’s AI can read, summarize, rewrite or help apps take action, attackers will try to trick it into doing things you never intended.
Apple Intelligence runs many AI tasks directly on your iPhone, but new research shows hidden prompts can still try to manipulate how it responds. (Getty Images)
So what can you do? Start by understanding how this attack works, why Apple patched it and which settings can lower your risk.
APPLE TAPS GOOGLE GEMINI TO POWER APPLE INTELLIGENCE
Join CyberGuy Live: Lock Down Your Phone in 30 Minutes (Saturday, June 13, 10 am ET)
- Your phone holds your email, passwords, photos, banking apps and personal data. In this free, live online class, Kurt the CyberGuy will walk you step by step through simple phone security fixes you can do in real time. You’ll learn how to improve your privacy settings, spot the latest phone scams, use trusted security tools and walk away with a simple checklist to stay protected. Register here: CyberGuyLive.com
What researchers found in Apple Intelligence
RSAC researchers tested the on-device large language model built into Apple’s operating systems. That’s important because third-party apps can access Apple Intelligence through system tools and APIs.
Their attack used two main techniques. The first, called Neural Exec, used strange-looking prompts designed to confuse the model and push it toward a specific response. The second used Unicode’s right-to-left override feature. That feature can make text appear in a different direction, which may help hide malicious instructions from filters while still influencing the model.
NEW EMAIL SCAM USES HIDDEN CHARACTERS TO SLIP PAST FILTERS
In simple terms, the attack tried to sneak instructions past Apple’s AI safeguards. The prompts may look meaningless to you and me. Yet the model may still interpret them as commands. That is where the risk grows. Apple Intelligence can connect to apps and system features. So a manipulated response could do more than produce a strange answer. In a worst-case scenario, attackers could try to manipulate data or functions available to an Apple Intelligence-enabled app, especially if that app has access to sensitive information.
Why Apple Intelligence prompt injection matters
Prompt injection is one of the biggest security problems facing AI tools. It happens when attackers hide instructions inside text that an AI model later reads. Think about a suspicious email, a strange document or a webpage with hidden text. You may see one thing. The AI model may process something else.
That creates a new kind of risk. An attacker may not need to break into your iPhone. They may only need to get a carefully crafted message, file or app input in front of the AI model.
OPENAI ADMITS AI BROWSERS FACE UNSOLVABLE PROMPT ATTACKS
If an app asks Apple Intelligence to summarize that content, rewrite it or act on it, the hidden prompt could try to steer the response. For you, that means AI safety now depends on more than strong passwords and software updates. It also depends on how well AI tools handle hostile instructions.
How Apple Intelligence works on your iPhone
Apple Intelligence uses a hybrid design. Some tasks run directly on your iPhone, iPad or Mac. More complex requests may move through Apple’s Private Cloud Compute system.
Apple has framed that setup as a privacy-focused alternative to cloud-only AI tools. That approach makes sense. Keeping more processing on your device can reduce how much personal data leaves your phone.
However, local AI does not automatically mean risk-free AI. RSAC’s research shows that deeper system access can create a larger attack surface. The more Apple Intelligence connects with apps and system features, the more important the guardrails become.
A simple writing tool carries one level of risk. An AI tool that understands personal context and works across apps carries a higher one.
Why this Apple AI security flaw raises concerns
The concern here goes beyond strange chatbot responses. Apple Intelligence can connect directly to apps through system-level tools. That means manipulated responses could affect how an app behaves. Researchers said the model could be pushed into generating offensive or unintended responses. They also warned that attackers could potentially manipulate data and functionality available to an affected Apple Intelligence-enabled app.
THOUSANDS OF IPHONE APPS EXPOSE DATA INSIDE APPLE APP STORE
RSAC estimated that between 100,000 and 1 million users may already be using apps with potential exposure. That estimate was based on apps Apple had identified as using the on-device LLM and RSAC’s rough calculations from App Store review data. That does not mean criminals are actively using this exact attack right now. RSAC said there was no public evidence of active exploitation when the research appeared. Still, the high success rate makes the findings hard to ignore.
What Apple has done about the iPhone AI risk
RSAC shared its findings with Apple before making the research public. According to RSAC, Apple hardened the affected systems against this attack in iOS 26.4 and macOS 26.4. Apple has not publicly detailed every change. That is common with security fixes, since companies often avoid giving attackers a roadmap.
The research appears to be a proof of concept, not a known active attack against everyday users. The most important takeaway for users is simple: keep your devices updated. Security patches only help if they reach your phone. If you delay updates for weeks or months, you may miss protections that close known gaps.
DON’T IGNORE APPLE’S URGENT SECURITY UPDATE
Ways to stay safe with Apple Intelligence
You do not need to stop using Apple Intelligence, but you should treat it like any powerful phone feature: keep it updated, limit what it can access, and stay careful with unfamiliar content.
1) Update your iPhone, iPad and Mac
Start with the easiest protection. Make sure your device runs the latest software.
On iPhone: Settings > General > Software Update
On Mac: Click the Apple menu in the upper-left corner of your screen > System Settings > General > Software Update
Turn on automatic updates when possible. That helps your device receive security fixes as soon as Apple releases them.
Researchers say crafted text and Unicode tricks helped bypass Apple Intelligence safeguards in tests, raising concerns about apps that connect to the on-device AI model. (Kena Betancur/Bloomberg)
2) Review your Apple Intelligence settings
If you do not use certain Apple Intelligence features, consider turning them off or limiting them. This can reduce how often AI tools interact with your apps, messages, summaries and personal content.
On iPhone: Settings > Apple Intelligence & Siri
From there, review which features are enabled. Turn off anything you do not need.
3) Be selective with AI-powered apps
Do not give every app access to sensitive information just because it offers an AI feature. Before installing an app, check the developer, reviews and privacy details. Also, ask yourself whether the app really needs access to your messages, files, photos or contacts. If the answer feels unclear, skip it.
DON’T GET CAUGHT IN THE ‘APPLE ID SUSPENDED’ PHISHING SCAM
4) Watch what you ask AI to summarize
Prompt injection can hide inside content that looks harmless. That could include emails, webpages, documents, notes or copied text. Be careful when asking AI to summarize unfamiliar content. A malicious file could contain hidden instructions meant for the AI rather than you.
5) Review app permissions
Take a few minutes to check which apps can access your private data.
On iPhone: Settings > Privacy & Security
Then review categories such as Photos, Contacts, Location Services, Microphone and Files. Remove access when an app no longer needs it.
6) Avoid pasting sensitive details into AI tools
Keep your most sensitive information out of AI prompts when possible. That includes Social Security numbers, banking details, tax documents, medical records and passwords. AI can help with many tasks. It should not become a dumping ground for your private life.
7) Delete apps you no longer use
Unused apps can put your data at risk. If you downloaded an app months ago and forgot about it, remove it.
On iPhone: Touch and hold the app > Remove App > Delete App > Delete
The fewer apps you keep, the fewer ways your personal data can move around.
8) Add strong antivirus software
Strong antivirus software adds another layer of protection against malicious links, scam websites, infected downloads and phishing attacks that may try to steal your personal information. While antivirus software will not directly stop every AI prompt injection risk, it can help block threats before they reach your device or trick you into handing over sensitive data.
The best antivirus software can also warn you about suspicious emails, dangerous attachments and fake websites. That extra protection becomes more important as scammers use AI to make attacks look more convincing. Get my picks for the best 2026 antivirus protection winners for your Windows, Mac, Android & iOS devices at Cyberguy.com
9) Consider identity theft protection
Identity theft protection will not stop a prompt injection attack. Still, it can help if your personal information gets exposed or misused. A good identity theft protection service can monitor your personal data, alert you to suspicious activity and help you respond if someone tries to open accounts or use your identity. As AI tools become more integrated with apps and personal data, that extra monitoring can provide another layer of protection. See my tips and best picks on Best Identity Theft Protection at Cyberguy.com
10) Use stronger iPhone security settings
Keep Face ID or Touch ID enabled. Use a strong passcode instead of a simple four-digit code. Also, turn on Stolen Device Protection if your iPhone supports it.
On iPhone: Settings > Face ID & Passcode > Enter your passcode if prompted > Stolen Device Protection
This will not stop prompt injection by itself. However, it adds another layer if someone gets physical access to your phone.
Kurt’s key takeaways
Apple Intelligence still has a strong privacy story. Running more AI tasks on your iPhone and using Private Cloud Compute for tougher requests gives Apple a real advantage over many cloud-only AI tools. But this research is a reminder that private does not always mean untouchable. If an AI model can read prompts, summarize content and connect with apps, attackers will look for ways to bend it to their advantage. For you, the takeaway is simple. Keep your devices updated, be selective about AI-powered apps and think twice before letting AI process sensitive information. Apple can build strong walls around your data, but you still decide what you invite inside.
Keeping your iPhone updated, limiting app access and being careful with unfamiliar content can help reduce your risk as AI becomes more deeply built into your device. (Sebastian Kahnert/Picture Alliance)
Would you trust an AI assistant more because it runs on your iPhone, or does deeper access to your personal data make you more cautious? Let us know by writing to us at Cyberguy.com
Sign up for my FREE CyberGuy Report
CLICK HERE TO DOWNLOAD THE FOX NEWS APP
- Get my best tech tips, urgent security alerts and exclusive deals delivered straight to your inbox.
- For simple, real-world ways to spot scams early and stay protected, visit CyberGuy.com – trusted by millions who watch CyberGuy on TV daily.
- Plus, you’ll get instant access to my Ultimate Scam Survival Guide free when you join.
Copyright 2026 CyberGuy.com. All rights reserved.
Technology
Nintendo’s Switch 2 bundle that includes a game is $50 off
Discounts on the Nintendo Switch 2 are rare, but they do happen on occasion. There’s one happening now, actually, on the company’s $499.99 console bundle that includes a digital game (Mario Kart World, Donkey Kong Bananza, or Pokémon Pokopia). Usually, the bundle saves you $20 or $30, depending on the game you choose, but for $449.99 at Amazon, Nintendo is effectively giving a game to you for free.
If you’re considering grabbing a Switch 2, I highly recommend doing so now. The biggest motivator (aside from its great selection of games and near-complete compatibility with original Switch games) is that the console will get a price hike in September, going from $449.99 to $499.99. Also, it’s not clear if it will continue to include a discounted game with purchase at that point. So, you’re getting more value at $449.99 here than ever before.
Technology
Humanoid robots perform live surgery in world first
Humanoid robot surgeons perform first-ever remote surgery, raising AI privacy concerns
A medical breakthrough was achieved as UC San Diego doctors successfully utilized $20,000 humanoid robots to perform remote gallbladder surgery on a pig. This development highlights the potential for artificial intelligence to address surgeon shortages and improve access to care globally. The discussion also delves into privacy concerns surrounding advanced AI robots, including a new $8K home robot for chores.
NEWYou can now listen to Fox News articles!
Humanoid robots have officially stepped up to the operating table, helping complete two surgeries for the first time. During the preclinical trial, surgeons remotely guided the machines through two gallbladder removal procedures. The robots copied the surgeons’ movements rather than making medical decisions, and no human patients were involved.
Unlike bulky robotic systems fixed in place, these five-foot machines used standard surgical tools and worked inside an operating room built for people. The experiment offers an early look at how a specialist could someday operate through a mobile robot in a rural clinic or another place where surgical care is hard to reach. Here is what the team accomplished and what still needs to happen before this technology reaches human patients.
AI MAY SPOT DEADLY HEART RISK IN A ROUTINE ECG
Free live CyberGuy class: Sick of Spam? Join us July 22
Join us Wednesday, July 22, at 1 p.m. ET for a free CyberGuy Live class that will help you cut down on robocalls, spam texts, junk email and other unwanted messages. Kurt “CyberGuy” Knutsson will walk you step by step through simple ways to filter spam, clean up your inbox and recognize the messages that could put your personal information at risk. No technical experience is needed. You’ll also receive our spam-stopping checklist, and every registrant will get a link to the class recording afterward.
Reserve your free spot today at CyberGuyLive.com.
Researchers say mobile humanoid robots could someday help bring specialist surgical care to rural clinics, field hospitals or remote locations. (UC San Diego Jacobs School of Engineering)
Two humanoid robots completed live surgeries
Researchers from the University of California San Diego reported the results in the journal Nature earlier this month. The team tested its system during two laparoscopic gallbladder removal procedures on pigs.
During one operation, a humanoid robot handled surgical instruments while a human surgeon assisted beside it. During the second procedure, two humanoid robots stood next to each other and worked as a team. Surgeons remotely controlled both robots throughout the operation. The experiment involved delicate tasks used during minimally invasive gallbladder surgery. The robots moved tissue and dissected around the gallbladder. They also helped place clips before removing it.
Researchers designed the trial as a proof of concept. They wanted to learn whether a general-purpose humanoid robot could handle standard surgical tools with enough control to complete an operation. It could. However, the trial also exposed problems that researchers must solve before testing the system on humans.
The trial marked the first time teleoperated humanoid robots successfully completed live gallbladder surgeries. Robotic gallbladder procedures have been performed before, but this experiment was the first to use general-purpose humanoid machines. The work builds on UC San Diego’s earlier research with the same type of robot. CyberGuy previously covered how a remotely controlled humanoid performed seven medical procedures, including physical exams and ultrasound-guided injections.
How these humanoid robots fit into a standard operating room
The researchers created Surgie by modifying commercially available Unitree G1 humanoid robots. Each machine stands about 5 feet tall and weighs around 60 pounds. That makes Surgie dramatically smaller than many existing robotic surgery systems, which can weigh approximately 1,800 pounds.
Large surgical robots may require extensive setup and take up considerable space. Hospitals sometimes need to retrofit an operating room before installing one. Surgie can stand in a room designed for human medical workers. Researchers added adapters to its hands so the robot could grip standard laparoscopic instruments.
A surgeon then controlled the robot from a remote console. When the surgeon moved the controls, Surgie copied those movements at the operating table. That human-like design is important. A hospital may be able to bring the robot into an existing room instead of rebuilding the space around it. A medical team could also move it between rooms or transport it to a smaller facility. “We were surprised at how well Surgie meshed with our workspace and workflow,” said Nikita Thareja, MD, a general surgery resident at UC San Diego School of Medicine and a co-author of the study.
Unitree currently lists the base G1 at $13,500 before taxes and shipping. However, that price does not include the surgical adapters, instruments or remote-control equipment used in the study. The price still points to a potentially significant difference between a general-purpose humanoid and today’s specialized surgical systems. Da Vinci surgical robots can cost from about $700,000 to more than $3 million, depending on the model and configuration. Researchers have not disclosed the total cost of the complete Surgie setup.
CHINA’S ROBOT-RUN HOTEL OPENS TO PUBLIC IN 2027
UC San Diego researchers remotely guided humanoid robots through two gallbladder surgeries on pigs in a preclinical trial.d (UC San Diego Jacobs School of Engineering)
Why use a humanoid instead of a surgical robot?
Modern robotic surgery systems already help doctors perform highly precise procedures. However, those machines usually stay in one location and depend on specialized equipment. A humanoid robot offers more flexibility because it can operate in spaces built for medical workers. It can also hold tools designed for human hands.
Researchers believe future versions could retrieve an instrument during surgery. The robot might also help prepare or clean the room after a procedure. Most importantly, a mobile system could potentially bring a specialist’s skills to an area where surgeons are difficult to find.
Michael Yip, a professor in UC San Diego’s Department of Electrical and Computer Engineering, said remotely operated humanoids could expand access to critical procedures. Researchers envision sending the robots to communities with limited medical staffing or temporary field hospitals.
The goal isn’t to hand medical decisions to a machine. A trained surgeon would remain in control while the robot carried out those movements at the patient’s location. That could give a trauma team on a battlefield access to a specialist located far away. The same approach could help a patient in a remote town avoid a long trip to a major medical center. Researchers have even discussed using the technology during future space missions.
That idea is already moving beyond the laboratory with traditional surgical robots. In March, we reported on a London surgeon who remotely removed a patient’s prostate cancer from 1,500 miles away. The difference is that the London procedure used a specialized surgical platform. Surgie could eventually offer a smaller system that works inside a standard operating room.
The robots still needed plenty of help
The successful procedures do not mean hospitals are ready to start using humanoid robots on patients. Researchers had to recalibrate the robots several times during surgery. The operations also took much longer than procedures performed with established surgical systems.
Latency presents another concern. Latency is the delay between a surgeon moving a controller and the robot responding. A slight lag may feel annoying during a video call. During surgery, even a small delay could affect precision. That challenge becomes more serious when the surgeon and robot are separated by a long distance.
Researchers will need to improve the robot’s reliability and response time. They must also prove that the system can repeat its performance safely across many procedures. Hospitals would need a backup plan as well. A qualified surgical team would have to remain ready to step in if the robot stopped responding or the remote connection failed.
Could a humanoid robot eventually operate on its own?
For now, human surgeons control Surgie’s movements. The UC San Diego researchers eventually want to develop what they call an autonomous surgical assistant. That type of robot could recognize which tool a surgeon needs or complete a limited task under supervision.
Researchers elsewhere are already testing a different approach to autonomous surgery. CyberGuy previously covered an AI-powered robot that independently completed a key phase of gallbladder removal on a lifelike surgical model. However, operating on a living patient presents a much greater challenge. Bleeding can begin without warning. A patient’s condition can also change in seconds.
A robot would need to recognize the problem and respond safely. Medical workers must also be able to take control immediately. Autonomous surgery raises difficult questions about responsibility. Hospitals would need clear rules covering who makes each decision and who is accountable when something goes wrong. Remote operation introduces another concern. Hospitals would have to protect the robot’s software and communications from unauthorized access. At the same time, the system would need to continue operating safely during a connection problem.
WOULD YOU PAY $8,000 FOR A ROBOT TO FOLD LAUNDRY?
Surgeons controlled the humanoid robots from a remote console while the machines copied their movements during live procedures. (UC San Diego Jacobs School of Engineering)
What this means to you
You will not see a humanoid robot independently performing your next surgery. This research remains at the preclinical stage, and the team tested the system on pigs rather than humans. Still, the experiment offers an early look at where robot-assisted medicine may be headed.
A mobile surgical robot could eventually give you access to a specialist without requiring a long trip. It may also help a smaller hospital offer procedures that currently require transferring patients elsewhere. However, access should never come at the expense of safety. Before agreeing to a robot-assisted procedure, you should know who controls the machine. You should also ask what happens if the connection fails and whether a qualified surgical team will remain in the room. The robot may hold the instrument, but human judgment remains the most important part of the operation.
Kurt’s key takeaways
Watching two humanoid robots work over an operating table may make you uncomfortable. Still, the technology could address a serious healthcare problem if researchers can make it reliable and safe. Many communities struggle to attract enough surgeons. A compact robot that works with standard instruments could let a distant specialist enter the operating room without physically traveling there. The comparatively low starting price of the base robot could also make this approach easier to deploy than some specialized surgical systems. This experiment remains an early milestone. The robots needed recalibration, and the operations took longer than usual. Communication delays also remain a concern. The researchers now need to prove that Surgie can perform consistently before anyone considers human trials. Hospitals will also need strict safety protections and trained medical workers ready to take over.
Would you let a surgeon operate through a humanoid robot if it cut months off your wait for care? Let us know by writing to us at CyberGuy.com.
CLICK HERE TO DOWNLOAD THE FOX NEWS APP
Sign up for my FREE CyberGuy Report
- Get my best tech tips, urgent security alerts and exclusive deals delivered straight to your inbox.
- For simple, real-world ways to spot scams early and stay protected, visit CyberGuy.com – trusted by millions who watch CyberGuy on TV daily.
- Plus, you’ll get instant access to my Ultimate Scam Survival Guide free when you join.
Copyright 2026 CyberGuy.com. All rights reserved.
Technology
Microsoft tests Windows Search without all the ads and fluff
Microsoft is testing a cleaner version of the Windows 11 search menu that strips it of recommended content and ads. In a blog post on Monday, Microsoft announced that it’s rolling out the decluttered Search Box to Windows Insiders in the Experimental channel as the company looks to regain trust with users and fix Windows.
One of the biggest changes is a revamped search homescreen that displays only your recent searches. Currently, when you open the search menu, it shows your recent searches alongside several distracting tiles on the right pane, containing things like the image of the day, daily quizzes, trending searches, and game recommendations.
Microsoft is cleaning up web results, too, as the search menu will surface the “most relevant answer” first, rather than showing “related products and promotions.”
Aside from doing some decluttering, Microsoft is testing other notable improvements to its search menu. It will more clearly show metadata, along with a preview of the file in the pane on the right side of the search menu, making it easier to figure out where the result came from. The Windows 11 search system will also prioritize results from your local files, apps, and settings, which will “more reliably appear” ahead of web and Microsoft Store recommendations. Testers can now turn off web and Store recommendations entirely from the Settings menu.
There are a few quality-of-life updates, too, as Microsoft says the search system it’s piloting can better handle typos, extra letters, and partial words, while offering some performance improvements.
-
Mississippi6 minutes ago
Mississippi Legislature to hold special session for youth court laws
-
Missouri12 minutes agoRoute 66 in Springfield, Illinois and St. Louis: Chasing Midwest food innovations on the Mother Road
-
Montana18 minutes agoGet Smitten With a Kitten at Humane Society of Western Montana
-
Nebraska24 minutes agoEPIC organizers launch fundraising petition effort to eliminate property taxes
-
Nevada30 minutes agoNevada Legislative Committee to meet in Lake Tahoe
-
New Hampshire36 minutes agoConcord City Manager Receives ‘Satisfactory’ Review, 2.5% Raise, But Sabbatical Request Gets Trimmed
-
New Jersey42 minutes agoNew Jersey high school teacher faces charges for allegedly having sex with student
-
New Mexico48 minutes agoIt’s a Boy! Giraffe born at Hillcrest Park Zoo in Clovis