Apple Intelligence Prompt Injection: On-Device AI Risks
April 12, 2026 · 4 min read
Apple Intelligence prompt injection is the headline, but the lesson is broader: on-device inference is not automatically “safe” inference. In early April 2026, security researchers at RSA Conference (RSAC) published work showing they could hijack Apple’s integrated on-device model—evading pre-filters, post-filters, and in-model guardrails—often enough to treat it as a practical attack, not a lab curiosity. Apple reportedly addressed the specific chain in iOS 26.4 and macOS 26.4 after responsible disclosure. The underlying issue—untrusted text steering a privileged assistant—remains an industry-wide problem.