A team of researchers from the Institute of Technology of Georgia and the University of Ruhr in Bochum have discovered two of the serious vulnerability of the canal side in the çipat M2/M3/M4/A15/A16/17 of the Apple to allow access to the sensitive data stored in the memory. FLOP and SLAP make use of the so-called execution spekulativ to bypass all the protections, similar to the weaknesses of the infamous Spectre and Meltdown.
Description of the vulnerability
As well as all of the device to the latest Apple M2/M3/M4/A15/A16/17 uses to run spekulativ, which is the charge on the storage of instructions that can be executed. Çipat M2/A15/A16 of the company's Cupertino provide also the address of the memory to access, while the çipat M3/M4/17 contemplate also the data returned from the cache. The submission may be used for the execution of the instructions of arbitrary data in the wrong.
The weakness FLOP, which stands for the Prediction of the Distribution of the Charge to be false, it has an influence on the Parashikuesin of the Value of the Load (LCP), which provides for the data returned from the memory before the CPU to start. The researchers have shown that, if the prediction is incorrect, the sensitive data can be read from the memory. Using Safari, and Chrome, and they took up the history of the site of Google's Maps, email and Protonit and events in the iCloud Calendar.
The weakness SLAP, the acronym for the Prediction Speculative Load the Address in the place of that has to do with the Parashikuesin the name and Address of the Load (LAP), which provides the address of the memory from which the CPU will be taken to the data. In this case, the assumption is wrong, it can also be used to perform the data can be found at the address of the memory with the instructions, arbitrary. Using Safari, you can use the emails in your Gmail, the traditions of the Amazon and other information to the browser.
FLAP is present only in the çipat Apple-M3/M4/17, while the SLAP is also present in the çipat Apple's M2/M3/M4/A15/A16/17. The company's Cupertino is planning to release the arnimeve. One in respect to the potential of the cache is off the new Year on Chrome and Safari, but it's going to cause problems with many web pages.
Discussion about this post