Apple Security Team found that a flaw in function execution can lead to privilege escalation across apps. With AI function integrations and tokenized permissions, inaudible audio injection becomes an attack vector. Whereas the original Siri sandbox restricted many critical functions, Apple Intelligence’s plan to expose photos, calendars, email, and other sensitive capabilities enlarges the attack surface, ultrasonic commands could effectively act as a covert control channel. A strict API scoping, hardware-backed token storage, and microphone/audio-path filtering and detection is need it, and that's what the fuss is all about.