Photo credit: www.androidauthority.com
Significant Security Vulnerabilities Discovered in Apple’s Chips
Two newly identified vulnerabilities in Apple’s A- and M-series chips have raised concerns regarding user data security. These weaknesses, reported to affect a range of Apple devices launched after 2021, may allow malicious actors to access sensitive information during web browsing on popular platforms such as Google Maps, iCloud Calendar, and Proton Mail using both Chrome and Safari browsers.
The investigation into these security flaws was conducted by researchers from the Georgia Institute of Technology and Ruhr University Bochum. They revealed that the vulnerabilities expose the chips to side-channel attacks, which are sophisticated exploits that can extract confidential information by analyzing external indicators such as timing and power consumption patterns. The researchers demonstrated potential exploits through techniques dubbed FLOP and SLAP, illustrating that attackers could harvest a user’s location history, calendar events, and even read email content from services like Gmail and Proton Mail.
Devices Impacted by the Vulnerabilities
The reported vulnerabilities affect various Apple devices, including:
- All MacBook Air and MacBook Pro models from 2022 to the present
- All Mac Mini, iMac, Mac Studio, and Mac Pro models from 2023 to the present
- All iPad Pro, Air, and Mini models from September 2021 to the present
- All iPhone models from September 2021 to the present
Given the widespread use of these devices, the implications of these vulnerabilities are considerable, affecting a broad user base.
In response to the findings, researchers reported their discoveries to Apple and provided a set of recommended mitigations to address the identified security issues. Although Apple stated that the vulnerabilities do not represent an immediate threat to users, the company has assured researchers that it is actively working on a fix and plans to release patches in the near future.
As cyber threats continue to evolve, the discovery of these vulnerabilities highlights the importance of ongoing security assessments and the need for timely updates to protect users’ sensitive information.
Got a tip? Talk to us! Email our staff at news@androidauthority.com. You can stay anonymous or get credit for the info, it’s your choice.
Source
www.androidauthority.com