This enables an interesting new kind of attack.
1. Attach an attack device to someone’s account.
2. ‘Poll’ the clipboard by pasting every ~5 seconds.
3. If the contents of the clipboard appear to be ‘secure’ (looks like shellcode, bitcoin address, url, etc), quickly replace the contents with an attack string with same datatype.
If you have an untrusted device attached to your Apple account, your local clipboard can no longer be trusted.