CyberHappenings logo
☰

Track cybersecurity events as they unfold. Sourced timelines, daily updates. Fast, privacy‑respecting. No ads, no tracking.

Apple Intelligence data collection practices revealed

First reported
Last updated
πŸ“° 1 unique sources, 1 articles

Summary

Hide β–²

Apple Intelligence, the AI framework powering various Apple applications including Siri, has been found to collect extensive contextual data from users. This data collection occurs even for simple queries and includes information from other apps running on the device. The data is sent to Apple's servers, raising privacy concerns. Apple has dismissed most of these findings as expected behavior. The discovery was made by Yoav Magid, a senior security researcher at Lumia Security, who presented his findings at Black Hat USA 2025. Magid's research highlights that Apple collects more data than necessary, even when using end-to-end encrypted apps like WhatsApp. Apple's initial response was to acknowledge the issues, but they later classified them as features mentioned in their privacy policies. The implications of this data collection are significant for both individual users and enterprises, as it raises questions about data privacy and the governance of AI tools in organizational settings.

Timeline

  1. 22.08.2025 22:47 πŸ“° 1 articles Β· ⏱ 25d ago

    Apple Intelligence data collection practices revealed at Black Hat USA 2025

    Researcher Yoav Magid presented findings at Black Hat USA 2025, revealing that Apple Intelligence collects extensive contextual data from users, including information from other apps running on the device. This data is sent to Apple's servers, raising privacy concerns. Apple initially acknowledged the issues but later dismissed them as expected behavior mentioned in their privacy policies. The implications for both individual users and enterprises are significant, as it raises questions about data privacy and the governance of AI tools in organizational settings.

    Show sources

Information Snippets

Similar Happenings

Fourth Spyware Campaign Targeting French Apple Users in 2025

Apple has notified French users of a fourth spyware campaign in 2025. The Computer Emergency Response Team of France (CERT-FR) confirmed the alerts on September 3, 2025. The campaign targets individuals based on their status or function, including journalists, lawyers, activists, politicians, and senior officials. The alerts are part of a series of notifications sent throughout the year, with previous alerts on March 5, April 29, and June 25. These alerts indicate that at least one device linked to the users' iCloud accounts may have been compromised in highly-targeted attacks. The campaign follows a previous incident involving a security flaw in WhatsApp (CVE-2025-55177) and an Apple iOS bug (CVE-2025-43300), which were used in zero-click attacks. Apple has been sending these notifications since November 2021. Apple introduced Memory Integrity Enforcement (MIE) in the latest iPhone models to combat memory corruption vulnerabilities.