BrokeIt - Trending Repos · All episodes: ↗

Paint GUIDs, LLM host control, iCloud email persists

2026-08-25 · 8 min

Listen · Apple Podcasts Listen · Spotify

Stories covered

Transcript

Intro

Sam: That pickle file you just downloaded? It's not a model... it's a rootkit.

Kai: This is Kai.

Sam: And this is Sam.

Kai: It's Tuesday, August 25th, 2026, and we have three fresh stories from the wild world of open source and dev tools.

Sam: Let's get into it.

Kai: Your friendly neighborhood LLM might be able to take over its own computer... using nothing but its own model file.

Sam: And it looks like Microsoft Paint and Photos are adding invisible watermarks to everything you create, even when you're totally offline.

Kai: Plus, a small but important update from Apple: your 'Hide My Email' addresses are finally getting a home on icloud.com.

LLMs could control their host machines by exploiting inference engines

Kai: So, let's start with this new proof-of-concept from researcher Boyd Kane. It's terrifying. He shows how an LLM can gain full control of the machine it's running on.

Sam: And to be clear, this isn't prompt injection. The model isn't tricking you. The model file itself is the weapon.

Kai: Exactly. The attack targets the inference engine—the software that actually runs the model. Specifically, it exploits engines that use Python's `pickle` format to load model weights.

Sam: Ah, pickle. The library that literally has a giant warning in the docs saying 'The pickle module is not secure. Only unpickle data you trust.'

Kai: But everyone does it! It's been standard practice for years. You download a `.pkl` or `.pt` file from Hugging Face and just... run it.

Sam: And that's the problem. Pickle can execute arbitrary code on deserialization. So this researcher crafted a model file that, when loaded, shells out and gives the attacker remote access. It's game over.

Kai: So the LLM is its own Trojan horse. That's... brilliant and horrifying.

Sam: This puts any developer who's just blindly downloaded a model from a repo at risk. It's a huge supply chain vulnerability.

Kai: This is why the `safetensors` format exists, right? It was designed by Hugging Face specifically to be a secure alternative to pickle.

Sam: Exactly. `safetensors` is just a tensor data container. It can't execute code. But adoption is still not universal. A lot of legacy projects and tutorials still point to pickled models.

Kai: So the bottom line for developers is: stop using pickle for untrusted models. Yesterday. If it's not a `.safetensors` file, you have to treat it like a random executable you found on the internet.

Sam: Because you literally are. And don't assume a high star count means it's safe. We all know how easy those are to fake.

MS Paint and Photos inivisibly watermark even locally generated output with GUID

Sam: Alright, next up: a researcher going by Xusheng has found that recent versions of MS Paint and the Windows Photos app are adding invisible watermarks to images.

Kai: Wait, what? MS Paint? The program we all used to draw squiggly lines in the 90s?

Sam: That's the one. But this applies to the new AI-powered features, like Cocreator in Paint. When you generate an image, it embeds metadata into the file.

Kai: Okay, so it's part of the C2PA standard, the Coalition for Content Provenance and Authenticity. That's for tracking AI-generated content, right? That seems to make sense.

Sam: It would make sense, but here's the twist. The researcher found that even if you opt out of cloud features and generate everything locally, the apps still add a GUID—a Globally Unique Identifier—to the image's metadata.

Kai: Hold on. A unique identifier? Tied to... what? My machine? My Microsoft account?

Sam: That's the million-dollar question. The post says the GUID seems to be generated on the fly and is consistent for a user session. It's not clear if it's linkable back to an individual, but the potential is there.

Kai: So every meme I crudely assemble in MS Paint now has a little invisible 'Kai Was Here' tag on it? That feels... invasive. Especially for an offline action.

Sam: Extremely. It turns a simple, local-first utility into a tracking device. The researcher notes that while this specific GUID might not be a 'supercookie,' the infrastructure is now in place to add one silently in a future update.

Kai: This is a big deal for anyone who values privacy. The expectation with a tool like Paint is that what you do on your own machine, stays on your own machine.

Sam: It's a classic case of a reasonable feature—AI content provenance—being implemented with a privacy-eroding footgun. The takeaway is to be wary of any new 'smart' features added to old, trusted tools.

iCloud+ Hide My Email addresses will remain on icloud.com

Kai: And finally today, Apple has quietly changed how iCloud+ 'Hide My Email' works. You can now manage your addresses directly on the iCloud.com website.

Sam: Right. Previously, you could only manage these burner email addresses from within an Apple device's settings—on your iPhone, iPad, or Mac.

Kai: Which was honestly a huge pain. If you were on a Windows or Linux machine and needed to create or manage an address, you were out of luck. You had to go find your phone.

Sam: So this is a quality-of-life update. You can now log into iCloud.com from any browser, see your list of generated emails, change what real inbox they forward to, or deactivate them.

Kai: Exactly! It makes the feature so much more useful for cross-platform developers or anyone who doesn't live exclusively in the Apple ecosystem.

Sam: Okay, but let's put on the tinfoil hat. Why now? By moving this to the web, Apple is centralizing another piece of user interaction on its own servers, outside the 'secure enclave' of the device.

Kai: I see your point, but isn't that a bit paranoid? The emails were always routed through their servers anyway. This is just a UI change. It's a net win for usability.

Sam: Is it? Or is it conditioning users to manage their privacy settings on the web, where they're more easily tracked and data-mined than on-device? For a company that sells privacy as a feature, moving things off the device feels like a strategic shift.

Kai: I think you're over-indexing on this. For developers, this means you can now reasonably recommend 'Hide My Email' to users regardless of their primary OS. That's good for security hygiene overall.

Sam: [sighs] Fine. It's more convenient. But I'm keeping my eye on it. Convenience is often the enemy of security.

Kai: So, to recap: we've got a new exploit that turns LLM model files into weapons, reminding everyone to use `safetensors`.

Sam: MS Paint is embedding invisible, unique-ish identifiers in your offline images.

Kai: And Apple is making 'Hide My Email' accessible on the web... much to your suspicion.

Sam: And before we go... did you see that new CLI tool on GitHub? `git-blame-someone-else`.

Kai: [laughs] No! What does it do?

Sam: It rewrites the commit history to pin a bug on a coworker of your choice. It's a joke, obviously, but the code is a pretty clever use of `git filter-branch`. Don't... don't actually use it.

Kai: That's our show for today! We'll be back tomorrow with more open source news. Don't go downloading any suspicious pickle files.

Sam: And check your images for invisible ink. See you tomorrow.

This show is made with AI: the hosts’ voices are synthetic and the scripts are AI-assisted. Every story links to its original source.