New Apple feature automatically changes your compromised passwords
Apple says iOS 27 will let Safari and Passwords automatically update eligible compromised accounts with strong passwords.
Intelligence analysis by GPT-5.4 Mini

At WWDC 2026, Apple introduced an Apple Intelligence-based password feature that goes beyond warnings. Safari and the Passwords app will be able to automatically change eligible weak or compromised passwords, with Apple emphasizing on-device processing and Private Cloud Compute.
Apple is adding a helper that does more than warn about bad passwords. It is like a locksmith that not only spots a broken lock, but also replaces it with a stronger one.
Analysis
What Apple announced
Apple says Safari and the built-in Passwords app already flag weak, duplicate, or compromised passwords, but they do not currently fix them on their own. That changes with a new Apple Intelligence-powered feature that Apple describes as acting "agentically" based on user behavior to secure passwords automatically.
How it works
The feature is slated for iOS 27 and is aimed at eligible accounts that can be updated to strong passwords. In other words, Apple is not just surfacing the problem; it is trying to carry the user through the remediation step as well.
Privacy and rollout
Apple says the new password manager behavior is built on its next-generation Apple Foundation Models and is designed with privacy in mind. According to the company, the models run on device and, when needed, through Private Cloud Compute, which Apple says does not store users' personal data or make it accessible to Apple or anyone else.
The article also says Apple Intelligence improvements and the agentic password manager are expected in iOS 27 later this year, with developer beta access available sooner for those who want to test it early.
Key points
- Apple is adding an Apple Intelligence-powered feature that can automatically update eligible compromised passwords.
- Safari and the Passwords app already warn about weak or duplicate passwords, but this goes further by taking action.
- Apple says the feature will arrive with iOS 27 and will use on-device models plus Private Cloud Compute.
- The company frames the system as privacy-first and says personal data is not stored or exposed when Private Cloud Compute is used.
If Apple’s system works well, it could make password cleanup much easier for ordinary users and reduce the number of accounts left exposed after a warning. Apple’s privacy-first framing and on-device processing could also make the feature easier for cautious users to trust.
The feature will only help with eligible accounts, so many weak or compromised logins may still need manual work. If the automation misfires or users do not trust it, the feature could end up being ignored, limiting its security benefit.



