• News/
  • https://www.bleepingcomputer.com/news/security/new-apple-cpu-side-channel-attack-steals-data-from-browsers/

New Apple CPU side-channel attacks steal data from browsers

BleepingComputer
·
Bill Toulas
·
Published Jan 28, 2025
·
Updated

A team of security researchers has disclosed new side-channel vulnerabilities in modern Apple processors that could steal sensitive information from web browsers. The Georgia Institute of Technology and Ruhr University Bochum researchers, who presented another attack dubbed 'iLeakage' in October 2023,  presented their new findings in two separate papers, namely FLOP and SLAP, which show distinct flaws and ways to exploit them. The flaws stem from faulty speculative execution implementation, the underlying cause of notorious attacks like Spectre and Meltdown. The FLOP and SLAP side-channel attacks target features aimed at speeding up processing by guessing future instructions instead of waiting for them can leave traces in memory to extract sensitive information. "Starting with the M2/A15 generation, Apple CPUs attempt to predict the next memory address that will be accessed by the core," explained the researchers to BleepingComputer. "Moreover, starting with the M3/A17 generation, they attempt to predict the data value that will be returned from memory. However, mispredictions in these mechanisms can result in arbitrary computations being performed on out-of-bounds data or wrong data values." These mispredictions can have real-world security implications, such as escaping the web browser sandbox and reading cross-origin personally identifiable information on Safari and Chrome, as demonstrated in the two papers. The attacks are executed remotely through a web browser using a ...

Read full article

Affected Software

7 affected components
Apple M2 processors
Apple A15 processors
Apple M3 processors
Apple A17 processors
Apple M4 processors
Apple Processor=M2/A15
Apple Processor=M3/A17
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses new side-channel vulnerabilities in Apple processors that can compromise sensitive information from web browsers.

2

What security implications are discussed in the article?

The vulnerabilities could allow attackers to extract sensitive data from users via their web browsers, posing significant privacy risks.

3

Which Apple processors are affected by the vulnerabilities?

The affected processors include Apple M2, A15, M3, A17, and M4 processors.

4

Who conducted the research on the Apple CPU vulnerabilities?

The vulnerabilities were disclosed by researchers from the Georgia Institute of Technology and Ruhr University Bochum.

5

What type of attack is highlighted in the article?

The article highlights side-channel attacks as the method used to exploit the vulnerabilities in Apple processors.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203