Apple shared technical details of Apple Reference Image on its Security Research blog, September 15, 2026.
The opt-in iPhone 18 Pro Main camera mode instructs the sensor to cryptographically sign pixel data at capture. A “secure digital negative” is stored on-device with pixel data, sensor metadata, and cryptographic timestamps.
When users develop the negative for verification, unprocessed data is sent to Private Cloud Compute for rendering in a verifiable environment. The resulting reference JPEG is unalterable and can be compared side-by-side with the editable photo in Photos.
Apple claims the system resists data injection, compromised OS, hardware attacks, and cryptographic attacks. Post-quantum signatures and a revocation mechanism allow Apple to revoke individual photos or entire sensors if fraud is detected.
Apple Reference Image capture unavailable at launch in EU and China; viewing APIs available on iOS/iPadOS/macOS 27. Apple positions it alongside SynthID support and C2PA metadata as a multifaceted authenticity approach.