/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

Researchers reveal an attack forcing iOS and macOS WebKit browsers to divulge secrets, like passwords and email content, of users who visit a malicious website

iLeakage is practical and requires minimal resources.  A patch isn't (yet) available.  —  Researchers have devised an attack …

Ars Technica Dan Goodin

Context & Ripple Effects

This disclosure extends a recurring WebKit security pattern in which hostile web content can affect iOS and macOS users, from Safari address spoofing to malicious-ad redirects exploiting WebKit code. The notable escalation here is alleged disclosure of sensitive page content rather than merely disruption or redirection.

It also arrives against a history of WebKit bugs remaining exposed while fixes are awaited, including a reported unpatched flaw with potential remote-code-execution consequences. That makes remediation speed central when a visit alone is the attack trigger.

First-order effects

  • Users of iOS and macOS WebKit browsers who visit a malicious site face a reported risk that passwords or email content could be divulged before a patch is available.
  • Apple must address a browser-engine issue that can affect WebKit-based browsing across its platforms, while users and site operators have limited protection if the attack requires only page rendering.

Second-order effects

  • The finding raises the security cost of WebKit's shared-engine model: a single browser-layer weakness can create a common exposure across Apple devices rather than remaining isolated to one app.
  • Security teams may put more weight on web-content isolation and browser update cadence, particularly after prior WebKit issues were used for malicious-ad-driven redirects.

Third-order effects

  • If browser attacks increasingly extract data through rendering or side-channel behavior, platform security will be judged not only on blocking code execution but also on preventing cross-site data disclosure.
  • The recurring disclosures point to sustained pressure for faster, more transparent browser-engine remediation; the corpus does not establish whether iLeakage will produce a lasting policy change.

The trend: iLeakage is one data point in the broader shift from overt browser compromise toward attacks that turn ordinary web-page visits into opportunities for data leakage.

Discussion

  • @LukaszOlejnik@mastodon.social Lukasz Olejnik on mastodon
    Every macOS/iPhone (2020+) susceptible to information leak, for example GMail password theft.  By visiting a website from Safari/Firefox.  CPU architecture attack.  Great research! https://ileakage.com/...  [images]
  • @asmodai@mastodon.social @asmodai@mastodon.social on mastodon
    We present iLeakage, a transient execution side channel targeting the Safari web browser present on Macs, iPads and iPhones. iLeakage shows that the Spectre attack is still relevant and exploitable, even after nearly 6 years of effort to mitigate it since its discovery.  —  https…
  • @steipete Peter Steinberger on x
    Apple had 408 days to mitigate this, and while the attack works on iOS and macOS, all we got was an experimental off-by-default workaround on macOS. https://ileakage.com/
  • @we1x Lukas Weichselbaum on x
    🔥 #spectre #iLeakage Looks like the lack of site isolation in Safari allows stealing credentials & sensitive data. https://ileakage.com/ seems like they got spectre working on apple silicon. Opt-in fix for mac, nothing you can do on iOS (you can't even switch away from Safari) [i…
  • @titanas Stefanos on x
    @steipete There has to be a very good back story about this. Can't imagine Apple would allow hundreds of their executive to be exposed like that, even if they run a modified OS for obvious security reasons.
  • @moo9000 Mikko Ohtamaa on x
    iLeakage: Speculative execution attack on Safari, iPhone, iPad and Mac, allowing a hostile website to extract your passwords and other secrets. https://ileakage.com/ The only way to be safe is to stop using Safari: At the time of public release, Apple has implemented a... [image]
  • @steipete Peter Steinberger on x
    @titanas If there is, where's the post from the fruit company about it?
  • @p3b7_ Charles Guillemet on x
    I'm still amazed by how powerful spectre attack is! It's also a good reminder that laptop and mobile devices are not designed for security. Don't store your valuable on these devices...
  • @danielgenkin Daniel Genkin on x
    After more than a year of embargo we can now show you how speculative attacks can extract sensitive information from the Safari browser on @Apple platforms. Check out our latest paper https://ileakage.com/. Great work by Jason Kim, @themadstephan and @yuvalyarom. [image]
  • r/technology r on reddit
    Hackers can force iOS and macOS browsers to divulge passwords and much more