Researchers reveal an attack forcing iOS and macOS WebKit browsers to divulge secrets, like passwords and email content, of users who visit a malicious website
iLeakage is practical and requires minimal resources. A patch isn't (yet) available. — Researchers have devised an attack …
Ars TechnicaDan Goodin
Context & Ripple Effects
This disclosure extends a recurring WebKit security pattern in which hostile web content can affect iOS and macOS users, from Safari address spoofing to malicious-ad redirects exploiting WebKit code. The notable escalation here is alleged disclosure of sensitive page content rather than merely disruption or redirection.
Users of iOS and macOS WebKit browsers who visit a malicious site face a reported risk that passwords or email content could be divulged before a patch is available.
Apple must address a browser-engine issue that can affect WebKit-based browsing across its platforms, while users and site operators have limited protection if the attack requires only page rendering.
Second-order effects
The finding raises the security cost of WebKit's shared-engine model: a single browser-layer weakness can create a common exposure across Apple devices rather than remaining isolated to one app.
Security teams may put more weight on web-content isolation and browser update cadence, particularly after prior WebKit issues were used for malicious-ad-driven redirects.
Third-order effects
If browser attacks increasingly extract data through rendering or side-channel behavior, platform security will be judged not only on blocking code execution but also on preventing cross-site data disclosure.
The recurring disclosures point to sustained pressure for faster, more transparent browser-engine remediation; the corpus does not establish whether iLeakage will produce a lasting policy change.
The trend: iLeakage is one data point in the broader shift from overt browser compromise toward attacks that turn ordinary web-page visits into opportunities for data leakage.
Every macOS/iPhone (2020+) susceptible to information leak, for example GMail password theft. By visiting a website from Safari/Firefox. CPU architecture attack. Great research! https://ileakage.com/... [images]
We present iLeakage, a transient execution side channel targeting the Safari web browser present on Macs, iPads and iPhones. iLeakage shows that the Spectre attack is still relevant and exploitable, even after nearly 6 years of effort to mitigate it since its discovery. — https…
Apple had 408 days to mitigate this, and while the attack works on iOS and macOS, all we got was an experimental off-by-default workaround on macOS. https://ileakage.com/
🔥 #spectre #iLeakage Looks like the lack of site isolation in Safari allows stealing credentials & sensitive data. https://ileakage.com/ seems like they got spectre working on apple silicon. Opt-in fix for mac, nothing you can do on iOS (you can't even switch away from Safari) [i…
@steipete There has to be a very good back story about this. Can't imagine Apple would allow hundreds of their executive to be exposed like that, even if they run a modified OS for obvious security reasons.
iLeakage: Speculative execution attack on Safari, iPhone, iPad and Mac, allowing a hostile website to extract your passwords and other secrets. https://ileakage.com/ The only way to be safe is to stop using Safari: At the time of public release, Apple has implemented a... [image]
I'm still amazed by how powerful spectre attack is! It's also a good reminder that laptop and mobile devices are not designed for security. Don't store your valuable on these devices...
After more than a year of embargo we can now show you how speculative attacks can extract sensitive information from the Safari browser on @Apple platforms. Check out our latest paper https://ileakage.com/. Great work by Jason Kim, @themadstephan and @yuvalyarom. [image]