- all contacts, including 3rd party messaging apps, with metadata (interactions, timestamps, other stats) - full address book - whether any app is installed - SSID of connected wifi
and formerly,
- medical info - device usage - screen time - device accessories
I don't keep anything mission critical on mobile, but this is still a gargantuan set of exploits, and each appear extremely straightforward to validate and pay out the security researcher (and maybe even patch). It's utterly tragic how Apple (and others) have devolved to become the same monolithic, careless organizations they once displaced.
I really, really hope something changes. Soon.