Researchers detail two Apple silicon side-channel attacks that could leak secrets: SLAP, affecting M2, A15, and newer chips, and FLOP, affecting M3, M4, and A17
Apple-designed chips powering Macs, iPhones, and iPads contain two newly discovered vulnerabilities that leak credit card information …
Ars Technica Dan Goodin
Related Coverage
- Side-channel attacks on Apple Silicon: SLAP & FLOP SLAP and FLOP
- New Apple CPU side-channel attacks steal data from browsers BleepingComputer · Bill Toulas
- Researchers uncover new side-channel attack methods on Apple chips SC Media
- Apple CPU Flaw May Let Hackers Steal Your Data: 8 Ways To Stay Safe Forbes · Alex Vakulov
- Apple to Patch Web Browser Vulnerabilities Affecting Recent Macs, iPads and iPhones MacRumors · Juli Clover
- SLAP and FLOP security flaws affect all current Apple devices, and many older ones 9to5Mac · Ben Lovejoy
- Apple Chips Vulnerability Exposes Credit Cards & Location History to Hackers Cyber Security News · Guru Baran
- Two Apple Silicon chip flaws could expose your private data to thieves AppleInsider · Andrew Orr
- Apple CPU security issue could let hackers steal user data from browsers TechRadar · Sead Fadilpašić
- Apple's in-house chips have security flaws that could expose your Gmail inbox to attackers Android Authority · Pranob Mehrotra
- Using an iPhone, iPad, or Mac? You might lose your data to hackers Digit · Mustafa Khan
- New SLAP & FLOP Attacks Expose Apple M-Series Chips to Speculative Execution Exploits The Hacker News
- Security researchers cite SLAP and FLOP vulnerabilities found in a wide array of Apple Silicon hardware O'Grady's PowerPage · Chris Barylick
- View article Phoronix
- Apple chips in Macs, iPhones, iPads can be hacked: Report NewsBytes · Akash Pandey
- Apple-designed chips powering Macs, iPhones, and iPads contain two newly discovered vulnerabilities that leak credit card information, locations, and other sensitive data from the Chrome and Safari browsers as they visit sites such as iCloud Calendar, Google Maps, and Proton Mail. — https://arstechnica.com/... @dangoodin@infosec.exchange · Dan Goodin
- Well this seems suboptimal. — “When the mouse cursor is over our demo webpage, our proof-of-concept opens Proton Mail's inbox in a new window, but uses the same process to render the inbox. This brings the inbox content into the address space, making it accessible with a sandbox escape. … @chris_hayes@fosstodon.org
- New speculative attacks on Apple CPUs Hacker News
- Speculation Attacks on Apple M3: SLAP and FLOP lobste.rs
- Apple Chips Can Be Hacked To Leak Secrets From Gmail, ICloud, and More Slashdot · BeauHD
- Newly discovered flaws in Apple chips leak secrets in Safari and Chrome Ars OpenForum
- Apple to Patch Web Browser Vulnerabilities Affecting Recent Macs, iPads and iPhones MacRumors Forums
Discussion
-
Phoronix
Michael Larabel
on x
Apple CPUs Affected By New SLAP & FLOP Side-Channel Attacks
-
@matthewdgreen
Matthew Green
on bluesky
New attacks on load address prediction, affects Apple Silicon. predictors.fail
-
@ethanschoonover …
Ethan J. A. Schoonover
on mastodon
Applying the most recent #macOS 15.3 security patch reset the hostname on my system (definitely should not happen). Spotlight index also nuked and failing to rebuild (mdutil is not indexing). — But at least I have the garbage AI summaries in Mail! — (yes, I know how to force…
-
@alexjplaskett
Alex Plaskett
on x
Two new side-channel attacks against Apple CPUs that can leak sensitive data from the processor's memory SLAP (Speculation Attacks via Load Address Prediction) and FLOP (False Load Output Predictions) https://predictors.fail/
-
@danielgenkin
Daniel Genkin
on x
Have an Apple device from the last few years? We have a new side channel attack for you. Checkout our work at https://predictors.fail/ Joint work with Jason Kim, Jalen Chuang and Yuval Yarom (@yuvalyarom). Could not have asked for a better team! [image]
-
@chandlerc1024
Chandler Carruth
on x
Thoughts on https://predictors.fail/ over where I regularly post: https://hachyderm.io/... (Reminder, I'm not active here, find me on hachyderm or bsky)
-
@steipete
Peter Steinberger
on x
Not these again... ends up being fixed by making CPU's for everyone slower. This time Apple's M series starting with M2. https://predictors.fail/
-
r/technews
r
on reddit
Apple chips can be hacked to leak secrets from Gmail, iCloud, and more | Side channel gives unauthenticated remote attackers access they should never have.
-
r/technology
r
on reddit
Apple chips can be hacked to leak secrets from Gmail, iCloud, and more | Side channel gives unauthenticated remote attackers access they should never have.
-
r/hardware
r
on reddit
SLAP and FLOP [speculative execution vulnerabilities in Apple Silicon]
-
r/apple
r
on reddit
Apple chips can be hacked to leak secrets from Gmail, iCloud, and more