logo

New Apple CPU side-channel attacks steal data from browsers

ID: 9d46a64b-9df7-5a75-9ac8-acee6fbdc2b0

STIX ID: report--9d46a64b-9df7-5a75-9ac8-acee6fbdc2b0

Feed Name: Bleeping Computer

Threat Score
70/100

Date Published: 2025-01-28

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

Researchers revealed two remote speculative-execution side-channel vulnerabilities in Apple M‑ and A‑series CPUs—FLOP (false load output prediction) and SLAP (speculative load address prediction)—that enable malicious JavaScript/WebAssembly on a webpage to escape browser sandboxes and leak cross-origin sensitive data such as emails, calendar events, location history and browsing activity; PoC demonstrations exist and Apple was notified but fixes were not yet available at the time of reporting.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.