Tech and AIApple M-Series Chips Are Vulnerable to Side-Channel Attacks

Apple M-Series Chips Are Vulnerable to Side-Channel Attacks

-


Security researchers from Georgia Institute of Technology and Ruhr University Bochum discovered two side-channel vulnerabilities in devices with Apple name-brand chips from 2021 or later that could expose sensitive information to attackers. Specifically, the vulnerabilities known as SLAP and FLOP skim credit card information, locations, and other personal data. Data can be gathered from sites like iCloud Calendar, Google Maps, and Proton Mail via Safari and Chrome.

As of Jan. 28, Apple is aware of the vulnerabilities.

“Based on our analysis, we do not believe this issue poses an immediate risk to our users,” an Apple representative told ArsTechnica. According to the researchers, Apple plans to release a patch at an undisclosed time.

The researchers have not found evidence of threat actors using these vulnerabilities.

Which Apple devices are affected?

The following Apple devices include vulnerable chips, according to the researchers:

  • All Mac laptops from 2022 to the present (MacBook Air, MacBook Pro).
  • All Mac desktops from 2023 to the present (Mac Mini, iMac, Mac Studio, Mac Pro).
  • All iPad Pro, Air, and Mini models from September 2021 to the present (Pro 6th and 7th gen., Air 6th gen., Mini 6th gen.).
  • All iPhones from September 2021 to the present (all iPhone 13, 14, 15, and 16 models, SE 3rd gen.).

What are the SLAP and FLOP vulnerabilities?

Both vulnerabilities are based on speculative execution, a cyberattack technique that uses indirect cues such as power consumption, timing, and sounds to extract information that would otherwise be secret. Contemporary Apple chips inadvertently enable speculative execution attacks because they use predictors that optimize CPU usage by “speculating.” In the case of SLAP, they predict the next memory address the CPU will retrieve data from. In FLOP, they predict the data value returned by the memory subsystem on the next access by the CPU core.

  • SLAP enables an attacker to launch an end-to-end attack on the Safari web browser on devices with M2/A15 chips. From Safari, the attacker could access emails and see what the user has been browsing.
  • FLOP lets threat actors break into Safari and Chrome web browsers on devices with M3/A17 chips. Once inside, they could read the device’s location history, calendar events, and stored credit card information.

SEE: Chinese company DeepSeek released the most popular AI chatbot on the App Store this week, ahead of OpenAI.

“There are hardware and software measures to ensure that two open webpages are isolated from each other, preventing one of them form (maliciously) reading the other’s contents,” wrote researchers Jason Kim, Jalen Chuang, Daniel Genkin, and Yuval Yarom on their Georgia Tech site about SLAP and FLOP. “SLAP and FLOP break these protections, allowing attacker pages to read sensitive login-protected data from target webpages. In our work, we show that this data ranges from location history to credit card information.”

The research highlights the dangerous potential of side-channel attacks, which both SLAP and FLOP take advantage of. Side-channel attacks are difficult to detect or mitigate because they rely on properties inherent to the hardware.

In March 2024, Apple silicon ran afoul of another side-channel attack called GoFetch.

What can users do about the vulnerabilities?

Users can’t apply mitigations to these vulnerabilities, since the vulnerabilities are rooted in the hardware.

“Apple has communicated to us that they plan to address these issues in an upcoming security update, hence it is important to enable automatic updates and ensure that your devices are running the latest operating system and applications,” the researchers wrote.

TechRepublic has reached out to Apple for more information.



Source link

LEAVE A REPLY

Please enter your comment!
Please enter your name here

Latest news

Tron Outpaces Ethereum by Over 5x in Global USDT Transactions

Tron appears to have become the dominant force in the global movement of USDT, recently beating Ethereum’s daily...

Jerome Powell has been good for bitcoin, and Trump says he won’t fire him

Yesterday afternoon, BTC rallied $2,400 in 15 minutes on the news that Donald Trump wouldn’t fire US Federal...

Here’s What Mark Zuckerberg Is Offering Top AI Talent

As Mark Zuckerberg staffs up Meta’s new superintelligence lab, he’s offered top tier research talent pay packages of...

Not all Bitcoin holding firms will avoid death spiral

Nearly 200 companies now hold billions...

Advertisement

MicroStrategy wannabes and the return of mNAV mania

Crypto traders invented the term ‘mNAV,’ a simplistic ratio to explain how much they overpay for crypto holdings....

ICEBlock, an app for anonymously reporting ICE sightings, goes viral overnight after Bondi criticism

ICEBlock, an iPhone app that allows users to anonymously report sightings of U.S. Immigration and Customs Enforcement (ICE)...

Must read

Tron Outpaces Ethereum by Over 5x in Global USDT Transactions

Tron appears to have become the dominant force...

Jerome Powell has been good for bitcoin, and Trump says he won’t fire him

Yesterday afternoon, BTC rallied $2,400 in 15 minutes...

You might also likeRELATED
Recommended to you