Apple visionOS 26 must disable ChatGPT connection for Apple Intelligence.

STIG ID: AVOS-26-015400  |  SRG: PP-MDF-993300 |  Severity: medium (CAT II)  |  CCI: CCI-000366 |  Vulnerability Id: V-282824

Vulnerability Discussion

The ChatGPT feature of Apple Intelligence allows DOD information to be downloaded from the DOD Vision Pro and processed by the ChatGPT application in the cloud. The ChatGPT feature of Apple Intelligence increases the risk of compromise of sensitive DOD information.

SFR ID: FMT_MOF_EXT.1.2 #47

Check

This check procedure is performed on the device management tool and the device.

Note: If an organization has multiple configuration profiles, the check procedure must be performed on the relevant configuration profiles applicable to the scope of the review.

In the visionOS management tool, verify the following controls are set to Disable (the text may vary, depending on the UEM/MDM product):
- Allow External Intelligence Integrations.
- Allow External Intelligence Integrations Sign-In.

On the Vision Pro (Apple Intelligence-capable device only), use one of the following methods:

Method #1
1. Open the Settings app.
2. Tap "General".
3. Tap "VPN & Device Management".
4. Tap the Configuration Profile from the visionOS management tool containing the restrictions policy.
5. Tap "Restrictions".
6. Verify "External intelligence integrations not allowed" and "Sign-ins with external intelligence integrations not allowed" are listed.

Method #2
1. Go to Settings >> Apple Intelligence & Siri >> ChatGPT.
2. Verify "ChatGPT" is grayed out and disabled.

If external AI apps are not disabled (for example, ChatGPT), this is a finding.

Fix

Install a configuration profile to disable ChatGPT and other external AI app connections for Apple Intelligence.

1. Set allowExternalIntelligenceIntegrations to "False".
2. Set allowExternalIntelligenceIntegrationsSignIn to "False".