Apple’s upcoming iOS 27, iPadOS 27, and macOS 27 will feature an agentic tool that automatically updates compromised website passwords, raising significant questions regarding security, authority, and user control.
Key Points
- The feature uses Apple Intelligence and Safari to navigate websites, replace weak passwords, and save new credentials as a Live Activity.
- Security experts warn that granting an AI agent authority to modify account credentials creates potential risks, including prompt injection and account lockouts.
- The system is currently in developer beta as of June 8, 2026, with specific security architecture and failure-handling protocols yet to be fully documented.
- Recommended safeguards include isolating credentials from the AI model, requiring biometric user approval for changes, and limiting the agent to password-only modifications.
- The tool aims to address the common security failure where users ignore breach notifications or fail to update compromised credentials effectively.