Apple introduced Apple Reference Image, an opt-in photo-authenticity capability for the iPhone 18 Pro and iPhone 18 Pro Max. In Reference mode, the phones’ new Main camera sensor signs image data at the pixel level during capture; Private Cloud Compute then develops that data into an unalterable reference image intended to serve as a digital negative. The Photos app displays the reference image beside the corresponding photograph, enabling users to compare it against later edits, and APIs for iOS, iPadOS, and macOS 27 will let third-party applications display the reference asset.
The feature arrives with Apple’s iPhone 18 Pro lineup, which runs iOS 27 and is scheduled to be available beginning September 18, 2026. Apple plans to add SynthID support later in 2026 to help identify AI-generated or AI-edited images. Reference Image will not be available at launch in China, while capture will be unavailable at launch in the EU; EU users can nevertheless develop and view existing reference images on Apple operating systems version 27.

Track how attackers are adapting to this technology.
1 event from the most recent confirmed update back to the earliest known activity.
Apple announced the opt-in Apple Reference Image photo-authenticity feature for iPhone 18 Pro and iPhone 18 Pro Max. In Reference mode, signed pixel-level sensor data is developed through Private Cloud Compute into an unalterable reference image that users and supported third-party apps can compare with the captured photo; Apple also disclosed launch restrictions for China and EU capture.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Follow how adversaries are adapting to this technology, and where it touches your stack today.
4 references tracked. Mallory keeps watching after this page renders.
helpnetsecurity.com
Open sourcemacrumors.com
Open sourcesupport.apple.com
Open sourceapple.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.