← Founder Blog
·7min·Startup & Tech· views

I Left the iPhone

I no longer believe Apple's security myth. Every smartphone can be breached — so look at actual security architecture, update policy, and your own threat model, not the brand image. A security myth must be proven against real attacks, and in that test the iPhone has already been breached many times.

I left the iPhone.

I no longer believe Apple's security myth.

I switched from iPhone to Galaxy. For me, that is quite an event. I used iPhones for a long time, and I'm not one to change a product I've grown used to without real reason. But this time I changed. Not because I simply wanted a new phone. I judged that the comparative advantages that once made me choose the iPhone are no longer as clear as they were — and above all, that I no longer have reason to hold the old trust in “security,” the advantage so long touted as the iPhone's strongest.

First, let me be clear about something. This is not a claim that the iPhone lacks security features. iOS contains a genuinely sophisticated defense system: code signing, sandboxing, permission controls, hardware-based security. The problem is that this and the consumer perceptions — “iPhones don't get breached,” “inherently safer than Android,” “if security matters, iPhone, period” — are entirely different claims. Looking at the actual attack record, the latter, simpler faith is hard to sustain.

Start with the most recent material. Apple's own security document for iOS 26.6, published July 27, 2026, lists vulnerability after vulnerability well beyond mere app crashes: a flaw letting a malicious app execute arbitrary code with kernel privileges, a flaw letting a malicious app bypass code-signing checks, a flaw letting an app escape its sandbox, a flaw exposing protected user data, an issue allowing sensitive information to be viewed on a locked device — all patched. This is not outside speculation; it is Apple's own published security documentation.

Just two months earlier, iOS 26.5 in May 2026 fixed issues involving privacy-setting bypasses, kernel memory layout exposure, kernel memory reads, access to sensitive user data, and screen capture. In other words, today's iOS, like every other giant operating system, is a system in which vulnerabilities are continually found and fixed. There is no basis for believing that being an iPhone places it in some specially partitioned safe zone of the attack surface.

The more important problem is that the vulnerabilities did not stay in the laboratory. Cases of actual exploitation have been confirmed repeatedly. In February 2025, patching CVE-2025-24200, Apple disclosed that a flaw capable of disabling USB Restricted Mode on a locked device may have been exploited in an extremely sophisticated attack against specific targeted individuals. The same advisory noted Apple was aware of reports that a vulnerability involving maliciously crafted photos or videos shared via iCloud links had also been used in targeted attacks.

A month later, in March 2025, a WebKit vulnerability was patched. By Apple's account, maliciously crafted web content could break out of the Web Content sandbox — and this flaw, too, may have been exploited in a highly sophisticated attack aimed at specific individuals. In security, the sandbox is the core boundary preventing apps and web content from crossing into other areas of the system. And a vulnerability escaping precisely that boundary was tied to real attacks.

April 2025 produced an even more direct case. iOS 18.4.1 fixed CoreAudio vulnerability CVE-2025-31200, where merely processing a malicious media file's audio stream could lead to code execution, along with CVE-2025-31201, allowing an attacker with arbitrary read/write capability to bypass Apple's Pointer Authentication. Apple acknowledged both may have been exploited in extremely sophisticated targeted attacks. Pointer Authentication is a key defense Apple uses to make memory attacks difficult — and a vulnerability bypassing even that line was found in a real attack context.

In August 2025, ImageIO memory-corruption flaw CVE-2025-43300 was urgently patched. Processing a maliciously crafted image file could corrupt memory, and Apple again said it may have been exploited in an extraordinarily sophisticated attack on specific individuals. The point: attacks don't require installing a shady program, as in the everyday notion of “hacking” — the image, web-content, message, and media-processing layers themselves can be the attack surface.

Nor did this story suddenly begin in 2025. One of the events that most shook the iPhone security myth is Pegasus. In 2023, Citizen Lab discovered the BLASTPASS exploit chain. It could infect iPhones running iOS 16.6 — the latest version at the time — without any action by the victim. The attacker delivered a PassKit attachment containing malicious images over iMessage; the user didn't even need to tap a link or open a file. A zero-click attack, in the literal sense.

The same family of attacks recurred before that. PWNYOURHOME, analyzed by Citizen Lab, was a two-stage zero-click chain attacking HomeKit and iMessage processes in sequence — and researchers explained it could succeed even against victims who had never once configured HomeKit. Infections found on multiple iPhones in 2022 confirmed these attacks were used in the real world.

FORCEDENTRY, analyzed by Google Project Zero, is more striking still. By merely sending a file over iMessage, the attacker triggered remote code execution through an image-processing vulnerability, then chained it into a sandbox escape. Project Zero researchers rated it among the most technically sophisticated attacks they had ever analyzed. Put differently: the iPhone's security architecture may raise the cost of attack, but for an attacker with sufficient resources and skill, it was no absolute barrier.

Amnesty International's forensic investigations likewise found evidence of iPhone 11 and iPhone 12 devices actually infected with Pegasus via iMessage zero-click attacks. That investigation even raised the possibility that thousands of iPhones were potentially affected. This too is a case where simple security folk wisdom — “iPhones don't get viruses,” “you're safe if you don't tap anything” — fails against real advanced attacks.

Of course, one distinction must be drawn precisely here. Pegasus-class attacks are mostly high-cost operations aimed at high-value targets — politicians, journalists, activists, diplomats — not indiscriminate crime against ordinary users. So the conclusion “every iPhone user gets hacked immediately” is also wrong. But that is not my complaint. My complaint is the claim that security is the iPhone's overwhelming comparative advantage. When real cases exist of the latest iOS being breached without a single click, and Apple itself patches actively exploited zero-days year after year, then at the very least the brand myth of “it's an iPhone, so relax” is not a realistic security model.

The other side is no longer the Android of the past, either. Samsung in particular has built a defense system through Knox — Secure Boot, a hardware Root of Trust, Arm TrustZone, hardware keys and tamper detection — and some recent devices ship Knox Vault, with a processor, memory, and secure storage independent of the main application processor. Per Samsung's documentation, Knox Vault is designed to protect sensitive information like encryption keys and credentials in separate secure hardware even if the main Android processor is compromised. This alone doesn't justify concluding “Galaxy is unconditionally safer than iPhone,” but at minimum, the decade-old dichotomy — “iPhone is the security phone, Android is sloppy” — no longer describes the actual technical architecture.

The update gap has narrowed greatly too. Samsung officially announced that from the Galaxy S24 series it provides seven generations of OS upgrades and seven years of security updates. Short update windows — once a defining weakness of the Android camp — can no longer be called a weakness of the old magnitude, at least for major Galaxy flagships.

So the conclusion I reached in moving to Galaxy is not “Samsung can never be breached.” No such phone exists. Quite the opposite. Any smartphone can be breached. Then rather than trusting the security image a particular brand has built, one should look at the actual security architecture, update policy, speed of vulnerability response, and one's own threat model. iPhones get breached; Galaxies can get breached. What matters is not who looks safer in the marketing.

From that vantage, the iPhone's comparative advantage shrinks greatly for me. Once, advantages like security, app quality, camera, performance, and ecosystem justified accepting the iPhone's constraints and high switching costs. But competitors' completeness has risen sharply, and in security no absolute sanctuary belonging to Apple alone exists. Open Apple's 2026 security documents yourself and you'll find kernel-privilege code execution, code-signing bypasses, sandbox escapes, and privacy-data access still being discovered today.

So I no longer receive “I use an iPhone for security” as I used to. The fact that parts of Apple's security design are excellent and the brand image that the iPhone is safe must be separated. That a single iMessage, a single piece of web content, a single image or media-processing path can become the penetration route for a sufficiently capable attacker has already been proven in reality, several times over.

I switched from iPhone to Galaxy. For me, a very big event.

But the bigger change is not the logo on the phone. The standard by which I evaluate products changed. I no longer credit a company's past reputation as a present comparative advantage. Having been rated safest in the past does not automatically make it safest now, and having been the most polished in the past does not make it the best product today.

If Apple builds an overwhelmingly good product again, I can buy an iPhone again anytime. And if Samsung falls behind, I will leave it too. Consumers owe companies no loyalty. Companies must win the consumer's choice anew with every generation.

And for me, at least right now, “it's an iPhone, so don't worry about security” is no longer a reason to buy.

A security myth is not sustained by faith — it must be proven before real attacks.

And in that test, the iPhone has already been breached many times.

Originally published on Brunch · August 19, 2026
L
Lee · Lee's Blueprint
Founder, MAEUM.io
Email [email protected]