Lifehacker notes that the macOS ChatGPT desktop app now includes an Apple Messages plug-in that runs on-device, enabling AI-assisted messaging: query your iMessages, draft replies, and even send messages with your approval, plus analyze your chat history for quick summaries; while useful, it raises privacy concerns about letting AI access sensitive conversations.
This week’s buzz centers on AirPods Pro with cameras, spurred by macOS 26.7 code and a Kino Sensor, plus a new Imaging framework and active vs. passive capture modes that pair images from both buds. The cameras are intended to scan the environment to aid Siri/AI rather than capture photos or videos, with a privacy indicator tied to capture. Bloomberg’s Mark Gurman says Apple is targeting a 2027 release with two versions (B790 and B798), not an imminent launch.
OpenAI’s ChatGPT update for macOS adds a native Apple Messages plugin that can read and search iMessage, SMS, and RCS chats on your Mac and prepare or send messages from within ChatGPT. Available on all plans (including ChatGPT Work and Codex), messages are sent only after user approval by default, with guidance on revocation and privacy considerations. The release also syncs pinned chats across Mac and iPhone, and introduces read-only Codex snapshot sharing, among other improvements; for now, the feature works only on Apple Silicon Macs, not Intel.
Microsoft Defender Experts linked more than 30 web domains to the MacSync Stealer infrastructure, tracing a macOS information stealer from payload delivery through exfiltration. The campaign uses interactive zsh terminals, curl-based payload retrieval, AppleScript-assisted execution, and staging in /tmp with HTTP PUT uploads carrying chunked data. Observed exfiltration patterns and recurring endpoints (/curl/, /dynamic?txd=, /gate build) reveal rotating infrastructure, while data collected includes credentials, keys, and sensitive files. Microsoft cautions users and urges monitoring of curl uploads, API-key headers, and domain changes; Apple’s macOS protections (Terminal paste protection, pasteboard blocking, AppleScript scanning) are also relevant. The report follows similar findings from RST Cloud, which noted a static API key across several domains and parallel C2 operation across a rotating set of domains.
Meta is launching a Mac app for its Meta AI chatbot that can share your screen, offer suggestions, answer questions, and generate content from what’s on your screen, with dictation across apps. The app also connects to Google Workspace and can tie into Instagram and Facebook ad campaigns, enabling it to pull data to create decks, docs, and spreadsheets and handle recurring tasks, signaling a shift toward a desktop productivity assistant to compete with rivals like Google Gemini, OpenAI’s ChatGPT, and Anthropic’s Claude.
MacRumors reports that the macOS 26.7 Release Candidate includes references to more than 10 unreleased Apple products, including AirPods with infrared cameras for Visual Intelligence, a foldable iPhone, OLED MacBook and iPad mini variants, an updated Siri Remote for a next‑gen Apple TV, and a new Home Hub, hinting at multiple launches ahead of Apple’s upcoming event.
A macOS 26.7 RC leak uncovers references to several unreleased Home devices, including HomePad, HomePod mini 2, a Home Accessory camera, a next-gen Siri Remote, a video doorbell, and more, signaling a major Apple Home lineup overhaul ahead of other hardware launches.
A macOS Tahoe 26.7 release candidate reportedly includes a demo video showing AirPods with cameras and a feature called Visual Intelligence, reigniting rumors of camera-equipped AirPods. The clip suggests sensors near the microphone area and a Siri tutorial, but Apple may have left test data in a beta, so there’s no guarantee of an imminent release; the product has been rumored since Jan 2025 and could appear at a future event. The video was discovered by AaronP613 on X.
Apple released iOS 26.6.1, iPadOS 26.6.1, visionOS 26.6.1, and macOS 26.6.2 with security fixes first revealed in beta builds; it also rolled out iOS 18.7.10 and iPadOS 18.7.10, with visionOS fix details coming soon.
A new macOS information-stealer, AmnesiaStealer, uses a streaming module to clone a victim’s Chromium profile into a headless browser, enabling live, authenticated-session control across 16 Chromium-based browsers via WebSocket and the Chrome DevTools Protocol. It can exfiltrate cookies, saved logins, browsing history, wallets, notes, documents, and keychain data, and is distributed through ClickFix on a fake GitHub page with a password-protected ZIP. This marks the first documented macOS malware to pair a cloned Chromium profile with CDP-based live remote control, allowing attackers to view a live screencast (~3fps) and execute actions through the victim’s browser. Users should avoid unknown terminal commands and maintain strong security practices.
A free tool called EasyDMG automates the macOS DMG install process—mounting the disk image, copying the app to Applications, and cleaning up—eliminating the traditional drag-and-drop flow and offering configurable options, with no telemetry but raised security concerns about bypassing developer warnings.
A 25-year Windows user switches to a MacBook Air (M5) and discovers that the large, responsive trackpad and macOS gestures redefine his workflow, making a mouse feel unnecessary; six months in, he calls the trackpad the standout feature and wouldn’t return to Windows.
Apple still supports iTunes in 2026, but it’s no longer a single hub: macOS uses separate Music, TV, and Podcasts apps with Finder-based device syncing, Windows has likewise split into multiple apps, and iTunes Store plus iTunes Match remain for legacy use; third-party tools can help manage libraries, keeping iTunes alive mainly for older setups.
The Netherlands’ NCSC warns attackers are exploiting a macOS Screen Sharing authentication bypass (CVE-2026-65400) to gain root access, with exploits observed on systems exposing port 5900 to the Internet. Once in, attackers can run apps, access files, and deploy a Monero cryptocurrency miner. Apple patched the vulnerability in macOS Tahoe 26.6.1 and newer releases (also Sequoia 15.7.9 and Sonoma 14.8.9). Users should update to the patched releases or disable Screen Sharing if not needed, as details on scope and impact remain limited.
A high-severity macOS flaw (CVE-2026-65400) in the screen-sharing feature is under active exploitation, allowing remote attackers to gain root access when port 5900 is exposed to the Internet. Affected systems can be controlled remotely, with attackers potentially installing malware or stealing data. Apple has patched the vulnerability for macOS Tahoe, Sequoia, and Sonoma. For now, reports indicate attackers are using the flaw to deploy Monero miners; best defenses include turning off screen sharing when not in use, blocking port 5900, and applying the latest updates or connecting via VPN/SSH when needed.