iOS had a reputation of being more secure and less attacked than other mobile systems. Some iOS app cybersecurity protections could be assumed in security assessments.
That is changing.
First, iOS is attacked at about the same frequency as Android devices. The methods may vary, but the pace has picked up.
Second, the existence and availability of advanced hacking tools, including AI, are increasing.
Third, medical device app attacks have caught up with other verticals. Medical app attack rates will likely continue to increase. Criminals pay premium rates for stolen medical data.
Threat modeling, threat actor profiles, and risk assessments for iOS app cybersecurity should reflect these changes.
You can get more details on these trends from various sources. (One example is https://digital.ai/resource-center/webinars/how-ai-reset-the-economics-of-attacking-apps.
Another indicator is that Apple is now making automatic cybersecurity updates to iOS. Starting with iOS 26.1 (and parallel iPadOS and macOS versions), Apple can deliver security releases without user notice or permission. (more detail at https://support.apple.com/guide/security/background-security-improvements-sec87fc038c2/web).
Background cybersecurity updates remove some of manufacturer burden in performing iOS cybersecurity updates. This also has implications for Cybersecurity Management Plans. Manufacturers should include these updates as part of postmarket strategy.
Apple intends for the background updates to be compatible with current apps. However, a manufacturer should not depend on this. This means:
Adding monitoring for when background updates occur.
More manufacturer testing of apps to ensure maintaining functionality, safety, and security.
The background security updates can reduce time to fix vulnerabilities. The downside is more testing to ensure the updates don’t break anything.
