New Apple CPU side-channel attacks steal data from browsers
ID: 9d46a64b-9df7-5a75-9ac8-acee6fbdc2b0
STIX ID: report--9d46a64b-9df7-5a75-9ac8-acee6fbdc2b0
Feed Name: Bleeping Computer
Researchers revealed two remote speculative-execution side-channel vulnerabilities in Apple M‑ and A‑series CPUs—FLOP (false load output prediction) and SLAP (speculative load address prediction)—that enable malicious JavaScript/WebAssembly on a webpage to escape browser sandboxes and leak cross-origin sensitive data such as emails, calendar events, location history and browsing activity; PoC demonstrations exist and Apple was notified but fixes were not yet available at the time of reporting.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
