Researchers detail two Apple silicon side-channel attacks that could leak secrets: SLAP, affecting M2, A15, and newer chips, and FLOP, affecting M3, M4, and A17
Apple-designed chips powering Macs, iPhones, and iPads contain two newly discovered vulnerabilities that leak credit card information …
It also sits alongside a separate WebKit-based secret-disclosure attack affecting iOS and macOS: the coverage points to multiple layers, from browser software to silicon, that can shape device-data exposure.
First-order effects
The disclosures put users of Macs, iPhones, and iPads powered by the named chip families at risk of sensitive-data leakage if the attack conditions can be met.
Apple must assess SLAP and FLOP separately across affected generations, because the reported exposure differs between the M2/A15-and-newer group and the M3/M4/A17 group.
Second-order effects
Security teams supporting mixed Apple fleets will need to track exposure by chip generation rather than treating Apple silicon as a single security boundary.
The findings reinforce the value of application- and browser-layer defenses, since prior coverage showed that malicious WebKit visits could expose user secrets without relying on a chip-level flaw.
Third-order effects
Repeated side-channel disclosures across processor vendors suggest that performance-oriented hardware behavior will remain a recurring security-review issue, not a one-time defect class.
If this pattern persists, device security will increasingly depend on coordinated mitigations across chip design, operating systems, browsers, and applications rather than on any one layer alone.
The trend: Apple’s latest disclosures are part of a broader shift toward treating processor microarchitecture as an ongoing attack surface across the full device-security stack.
Applying the most recent #macOS 15.3 security patch reset the hostname on my system (definitely should not happen). Spotlight index also nuked and failing to rebuild (mdutil is not indexing). — But at least I have the garbage AI summaries in Mail! — (yes, I know how to force…
Two new side-channel attacks against Apple CPUs that can leak sensitive data from the processor's memory SLAP (Speculation Attacks via Load Address Prediction) and FLOP (False Load Output Predictions) https://predictors.fail/
Have an Apple device from the last few years? We have a new side channel attack for you. Checkout our work at https://predictors.fail/ Joint work with Jason Kim, Jalen Chuang and Yuval Yarom (@yuvalyarom). Could not have asked for a better team! [image]
Thoughts on https://predictors.fail/ over where I regularly post: https://hachyderm.io/... (Reminder, I'm not active here, find me on hachyderm or bsky)
Apple chips can be hacked to leak secrets from Gmail, iCloud, and more | Side channel gives unauthenticated remote attackers access they should never have.
Apple chips can be hacked to leak secrets from Gmail, iCloud, and more | Side channel gives unauthenticated remote attackers access they should never have.