The latest version of the Mac operating system, macOS Sequoia, is a pretty solid update that adds some great features, one of which is iPhone mirroring output. You can connect your Mac to your iPhone, have your phone appear on your desktop, and operate it as if you were holding the phone in your hand, which is a cool new feature, but obviously it’s not perfect.

macOS Sequoia’s iPhone mirroring output may leak personal data
According to security unit Report by Servco Security, there is a privacy vulnerability in iPhone mirroring output. When exporting using iPhone mirroring, if you use an app on your iPhone, the app will create an entry in your Mac’s directory. It may not sound like a big deal, especially if you’re using a personal Mac, but if you’re using a company Mac, your IT department may run a tool to track how your work Mac is doing. Your company’s IT staff can see the records created, so IT tools can figure out what apps you have on your personal iPhone, and they’ll know you’ve been browsing e-commerce apps when you should be working.

This Apple vulnerability is a significant privacy risk for iPhone users, as it could expose aspects of their personal lives that they don’t want to share, or could put them at risk. This could include VPN apps exposing their sexual orientation in countries that restrict access to the web, dating apps exposing their sexual orientation in jurisdictions with limited protection or legal consequences, or sharing apps related to health conditions that employees simply don’t want. The consequences of such data exposure can be severe. For companies, the error represents new data responsibilities that may collect private employee data. If Apple does not address this error, it could result in violations of major privacy laws such as the CCPA, potential litigation, and enforcement by federal agencies.

Servco reported the vulnerability to Apple on September 27 and received confirmation on October 3 that Apple was working on a fix. Security companies often publish their findings publicly after reporting security vulnerabilities to product manufacturing companies. The fix may appear in a future Sequoia update, possibly as part of the macOS 15.1 release later this month.

Apple releases security patches through operating system updates, so it’s important to install them when available. If Apple withdraws an update, the company will promptly republish the update with appropriate modifications and corrections. At the same time, the best way to avoid this vulnerability is not to export your private iPhone image to your work Mac.
Source: KOCPC Chinese