Cursor Mobile Launches, Taking AI Coding Agents to the iPhone
Anysphere’s Cursor is best known as a desktop AI code editor whose agents can understand codebases and perform coding, debugging and testing tasks. Cursor Mobile brings that workflow to the iPhone, freeing engineers from their computers and shifting their focus from writing code line by line to assigning tasks, reviewing changes and approving results.
Cursor announced the public beta of its iOS app on June 29, 2026, making it available across all paid plans. The App Store lists the app as free to download with in-app purchases. Users can select a repo and launch a cloud agent, issue instructions by voice or slash command, and use Remote Control to take over a desktop agent. They can also track progress, receive push notifications, review diffs and merge PRs directly.
All Coverage
2 original reportsThe Backstory
The history behind this eventCursor Expands Self-Hosted Cloud Agents With Team Resource Pools
Cursor’s Cloud Agents automate software-development work by running commands and modifying code, but enterprises often require tighter control over where those operations occur. The self-hosted model keeps command execution and code access inside a company-managed environment, while Cursor’s cloud continues to handle model inference and task planning. The split architecture is aimed at organizations seeking AI-assisted development without moving sensitive repositories or execution workloads outside their existing security perimeter.
Cursor has expanded self-hosted Cloud Agents to support eight additional infrastructure providers and platforms, including Cloudflare and AWS Lambda. The update also introduces team resource pools, allowing organizations to centrally provision and share compute capacity instead of requiring each developer to maintain a separate agent environment. Cursor did not disclose a specific release date or pricing in the supplied report, but the changes broaden deployment options for companies standardizing agent-based development across engineering teams.
Sandbox Flaws Let Cursor, Codex and Gemini Agents Reach Host Systems
AI coding agents can edit files and run shell commands, making sandboxing a critical barrier against mistakes, prompt injection and malicious repositories. Pillar Security said Cursor, OpenAI’s Codex CLI, Google’s Gemini CLI and Antigravity exposed indirect paths around that boundary. Rather than breaking isolation directly, an agent could alter workspace settings, Git configuration or Python virtual-environment files that trusted tools later execute outside the sandbox; in some setups, Docker could also provide access to the host.
The findings were reported on July 21, 2026. Cursor’s Python virtual-environment flaw affected releases before 3.1.2 and was fixed in 3.1.2, while CVE-2026-48124 affected Cursor Desktop 2.4.37 and was patched in 3.0.0. OpenAI corrected Codex CLI’s incomplete validation of supposedly safe Git commands in version 0.95.0. Pillar also described a macOS scenario involving Docker Desktop, Dev Containers CLI and network-enabled Auto-Run Sandbox mode that could let an agent access a user’s home directory and run host commands without another approval prompt.
Cursor Launches Composer 2 Series of AI Models Built for Coding
Cursor is an AI code editor developed by U.S. startup Anysphere. The company launched Composer 2 on March 19, 2026, using Moonshot AI's open-weight Kimi K2.5 as its foundation and applying continued pretraining on code and large-scale reinforcement learning. The model targets agentic development tasks spanning multiple files and hundreds of steps, reflecting a push by AI development-tool providers toward specialized models that balance performance and cost.
Official tests showed Composer 2 scoring 61.3% on CursorBench, ahead of Claude Opus 4.6 High at 58.2%. The standard version was priced at $0.50 per million input tokens and $2.50 per million output tokens. Anysphere confirmed on March 27 that it had used Kimi K2.5, then launched Composer 2.5 on May 18. The newer model's Terminal-Bench 2.0 score rose to 69.3%, while the Fast version was priced at $3 per million input tokens and $15 per million output tokens.
Subscribe to Mark Radar Weekly
Every Friday, the week's strongest signals in your inbox. Unsubscribe anytime.
If you search news on Google, you can set Mark Radar as a preferred source—our coverage will show up more often in your results. Set as preferred source on Google →