Skip to main content

Apples M1 and A14 Chips have an unfixable security flaw, but you need not worry too much about it

ARM-based M1 Chip, the first Apple-designed SoC developed for Macs and the iPad Pro, has a security vulnerability that allows two applications to covertly exchange data between them without going through proper channels. The vulnerability was accidentally spotted by a developer, Hector Martin, while he was working on porting Linux to the M1. He says that the flaw exists at the hardware level and can not be fixed by a software update. Apple was notified of the issue 90-days prior to the developer making the issue public and has already acknowledged it. 

Hector, however, notes that this flaw isn’t something users need to worry about. 

Here’s how the developer describes it: 

“A flaw in the design of the Apple Silicon “M1” chip allows any two applications running under an OS to covertly exchange data between them, without using memory, sockets, files, or any other normal operating system features. This works between processes running as different users and under different privilege levels, creating a covert channel for surreptitious data exchange.

The vulnerability is baked into Apple Silicon chips, and cannot be fixed without a new silicon revision.”

Users need not worry

The cause appears to be Apple violating an AMR specification requirement. At worst the flaw can be exploited by advertising companies for cross-app tracking. Users don’t have to really worry about malware exploiting this to take over their devices or steal their data. 

Martin also has a proof-of-concept video on his website that demonstrates that the covert channel can be used to transfer enough data to stream a video in real-time with few or no glitches. 

The flaw also affects iPhone 12 series that’s powered by A14 Bionic, since both the A14 and M1 are based on the same micro-architecture. The flaw is also expected to affect the next generation M1X chip that will reportedly be used in the upcoming MacBook Pro. It’s likely to get fixed in the iteration following that. 



from Latest Technology News https://ift.tt/3wA2Bo2

Comments

Popular posts from this blog

PS5 unboxing videos show how huge the console is

To say that Sony has been a bit coy when it comes to the PlayStation 5 would be a bit of an understatement. The company only recently announced the India pricing of the console and now finally we have unboxings of the console going live and one thing is pretty clear - The console is HUGE!  So what do you get in the box? Well… besides the console itself (and the manuals), you get: DualSense controller USB Type-C charging cable for the controller HDMI 2.1 cable Power cable for the console (no bulky adapter/box) Plastic stand Now the plastic stand is used if you place the console on its side. As there is no flat surface on either side of the console, the stand will ensure that it remains still. But you can also place it when propping up the console vertically. However, it does seem like the PS5 can stand on its own vertically if need be. IGN’s unboxing video gives you a good idea of how to place the stand. All of the unboxing videos mention the size of the console because it is pr...

Pixel 4a (5G) Model Tipped in Google Camera v7.5 App Code, Pixel 5 XL May Not Launch This Year: Report

Google Camera app version 7.5 teardown, rolled out for Android 11 beta users, shows mentions of three upcoming Pixel devices - Pixel 4a, Pixel 4a (5G), and Pixel 5, with no reference to the Pixel 5 XL. This hints that Google may be ditching the Pixel 5 XL this year. The codenames of the three upcoming Pixel devices are listed to be sunfish, bramble... from Gadgets 360 https://ift.tt/3gd9bJp