iPhone 18 Pro is available in black, silver, glacier and burgundy. Credit: Apple “An image appearing photorealistic is no longer sufficient to establish its veracity,” Apple’s security engineers wrote as they set out how the iPhone 18 Pro will prove a photo is real. Apple published the design of Apple Reference Image on its Security Research blog on 15 September. The post comes from its Security Engineering and Architecture team (SEAR) and its Camera and Photos group.
Reference Image is an opt-in camera mode. It runs on the main camera sensor of the iPhone 18 Pro and Pro Max, which Apple unveiled on 9 September. The post followed the release of iOS 27 on 14 September. Reviews of the new phones appeared a day later.
Why Apple did not build on C2PA Most of the industry uses the C2PA standard, which OpenAI adopted in May. Apple wrote that those systems attach provenance metadata after capture and certify edits from that point on. According to Apple, an attacker can compromise that chain at any step, and a viewer has no way to detect it. The company also said that tying an image to a public identity can put photographers in dangerous places at risk.
Apple set three requirements instead. A reference image must faithfully show what the sensor captured. Tampering with the sensor or jailbreaking the phone must not undermine it. An outside observer must not be able to tell whether two reference images came from the same device.
How the sensor signs a photo The process starts in the factory. Each image sensor creates its own signing key and never releases the private half. The Secure Enclave on the phone creates a separate key. A signed device manifest then binds the two, so Apple can later check that a sensor and an enclave belong to the same iPhone.
When a user switches to Reference mode, the sensor reboots into a secure state. It signs the pixel data straight after capture, and its firmware cannot change that data. The Secure Enclave signs metadata that comes from outside the sensor, such as digital zoom and focal length. Apple does not trust the phone’s own clock.
On a regular heartbeat, the phone receives a signed timestamp from Apple’s timestamp service through its push notification system. Worldwide, this happens about every 15 minutes on average. The latest token sets the earliest possible capture time. After the shot, the phone requests a second token as the latest possible time.
Apple says it guarantees the photo was taken between the two. The phone stores everything as a “secure digital negative” in DNG format. A photographer can also share that negative before it is developed. Development in Private Cloud Compute To develop the negative, the phone uploads it to Private Cloud Compute (PCC), the servers Apple uses for Apple Intelligence.
PCC verifies every signature and confirms that the sensor and the enclave come from the same phone. It then handles demosaicing, tone mapping and compression to JPEG. If the earliest timestamp fails verification, PCC uses 31 March 2026 instead, because the feature did not exist before that date. A neural network with hidden weights also scores whether the image looks like raw output from Apple’s sensors.
Apple signs the final image with a composite post-quantum signature that combines RSA-3072 and ML-DSA-87. The company wrote that an image “asserted to be authentic in 2026 should be securely verifiable in perpetuity”. Apple says its PCC design stops even Apple from seeing the image. Timestamp requests travel over Oblivious HTTP, so the service never learns the phone’s IP address.
After development, the negative moves to the deleted photos folder, and the phone purges it after 30 days. How Apple can revoke an image A companion service records each photo’s ID, the sensor ID and the confidence score, and keeps a running score for every sensor. If Apple revokes a low-scoring sensor, PCC stops signing its images. Apple devices download revocation lists and run the final check locally.
Epic Games chief executive Tim Sweeney pointed to that record on X. “Though users can’t determine whether two photos are from the same user, Apple can,” he wrote. Apple’s post says the record stays private and never includes image data. Watermarks have had mixed results so far. Google’s SynthID debunked a fake image of Mitch McConnell in July.
That same month, Meta’s own detector missed many cropped images from its own model. What the first reviewers found Engadget reviewer Cherlynn Low found the mode one swipe away from the default Photo mode. Each shot saves two versions, one of them a DNG file that the user develops in the Photos app. Her reference images developed “almost instantly”, she wrote, but the step needs an internet connection.
She called it “a pretty basic tool”. Engadget lists the iPhone 18 Pro from $1,199. Jaron Schneider of PetaPixel wrote that users must switch the feature on in Settings first. It only works on the main camera, at 1x and 2x.
The Photos app tracks later edits and shows a before and after view. Only the iPhone 18 Pro supports it at launch, according to Schneider. He wrote that Apple plans to bring support to computers and browsers later. Also tagged with













Leave a Reply