• News/
  • https://www.theregister.com/2025/01/29/flop_and_slap_attacks_apple_silicon/

SLAP, Apple, and FLOP: Safari, Chrome at risk of data theft on iPhone, Mac, iPad Silicon

The Register
·
Thomas Claburn
·
Published Jan 29, 2025
·
Updated

Many recent Apple laptops, desktops, tablets, and phones powered by Cupertino's homegrown Silicon processors can be exploited to reveal email content, browsing behavior, and other sensitive data through two newly identified side-channel attacks on Chrome and Safari. On Tuesday, security researchers Jason Kim, Jalen Chuang, and Daniel Genkin from the Georgia Institute of Technology in the US, and Yuval Yarom from Ruhr University Bochum in Germany, published papers describing two speculative-execution attacks dubbed SLAP [PDF] and FLOP [PDF]. These attacks exploit weaknesses in Apple's Arm-compatible processor designs to extract information from memory that should be off limits. In practice, that means a malicious webpage in one Chrome or Safari browser tab snooping on a page in another tab and stealing its sensitive information, such as emails being read and what have you. SLAP and FLOP build on Spectre, the 2018 microarchitecture attack that abused CPU speculation, in which processors try to accelerate operations by predicting the flow of execution through program code. By speculatively computing possible branches in logic in advance and discarding paths that aren't needed, CPUs can run applications faster. But the risk is that these speculative actions, even if discarded, can have observable side effects on shared resources – think caches or buffers – and it's these side effects that can be used by malware and rogue users to infer sensitive data, such as encryption keys, fro...

Read full article

Affected Software

9 affected components
Apple Chrome
Apple Safari
Apple M2
Apple M3
Apple A15
Apple M4
Apple A17
Apple Chrome
Apple Safari
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What security vulnerabilities are highlighted in the article?

The article discusses two new attack vectors, known as SLAP and FLOP, that can exploit Apple Silicon devices.

2

Which devices are affected by the described security vulnerabilities?

The vulnerabilities affect recent Apple laptops, desktops, tablets, and phones powered by Apple Silicon processors.

3

What type of sensitive data can be exposed through these attacks?

The attacks could potentially reveal users' email content, browsing behavior, and other sensitive information.

4

Which web browsers are specifically mentioned as being at risk?

Both Apple Safari and Google Chrome are identified as vulnerable to these attacks.

5

What Apple Silicon chips are mentioned in relation to these security issues?

The affected Apple Silicon chips include M1, M2, M3, A15, and A17.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203