SLAP, Apple, and FLOP: Safari, Chrome at risk of data theft on iPhone, Mac, iPad Silicon
ID: 736df2cd-b496-5262-a426-50144e997fb2
STIX ID: report--736df2cd-b496-5262-a426-50144e997fb2
Feed Name: The Register (Security)
Researchers disclosed two speculative-execution side-channel attacks named SLAP and FLOP against Apple Silicon (M-series, A-series) that can allow a malicious webpage or script to read sensitive data (emails, location, calendar entries) from other browser pages by abusing the CPU's Load Address Predictor and Load Value Predictor; proof-of-concept code and demos were published, mitigations such as setting the Data Independent Timing (DIT) bit and browser hardening are proposed, and Apple has been notified but states it does not see an immediate risk.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
