home.social

#ileakage — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #ileakage, aggregated by home.social.

fetched live
  1. #iLeakage, la faille qui exploite Safari et les puces Apple pour faire fuiter des informations
    nextinpact.com/article/72770/i
    Sur #iOS et #macOS, il est possible de forcer le navigateur Safari à révéler des informations sensibles, jusqu’aux mots de passe. Pour fonctionner, la méthode exploite également les puces #Apple. Elle demande cependant quelques conditions, dont… du temps.

  2. Exploiting WebKit on Apple silicon

    "The researchers implement iLeakage as a website. When visited by a vulnerable macOS or iOS device, the website uses JavaScript to surreptitiously open a separate website of the attacker’s choice and recover site content rendered in a pop-up window. The researchers have successfully leveraged iLeakage to recover YouTube viewing history, the content of a Gmail inbox—when a target is logged in—and a password as it’s being autofilled by a credential manager. Once visited, the iLeakage site requires about five minutes to profile the target machine and, on average, roughly another 30 seconds to extract a 512-bit secret, such as a 64-character string..."

    "For the attack to work, a vulnerable computer must first visit the iLeakage website. For attacks involving YouTube, Gmail, or any other specific Web property, a user should be logged into their account at the same time the attack site is open. And as noted earlier, the attacker website needs to spend about five minutes probing the visiting device. Then, using the window.open JavaScript method, iLeakage can cause the browser to open any other site and begin siphoning certain data at anywhere from 24 to 34 bits per second."

    arstechnica.com/security/2023/

    #opsec #infosec #security #tech #Apple #exploit #webkit #MacOS #iLeakage

  3. Monoculture by fiat produces predictable result:

    "As Apple requires all browsers on its App Store to be based on WebKit, third-party browsers on Apple devices, like Chrome and Firefox, are essentially just Safari with proprietary wrappers on them that add functionality, and are therefore vulnerable to the attack."

    Ready for a conflagration, just as in nature!

    #iLeakage
    #AppleMonoculture

    theregister.com/2023/10/26/ile

  4. Schwere Sicherheitslücke bei Apple: iPhones, iPads und Macs betroffen

    Apple sieht sich mit einer schwerwiegenden Sicherheitslücke konfrontiert. Noch scheint keine Lösung für das Problem in Sicht zu sein.

    t3n.de/news/sicherheit-apple-i
    #Apple #iPhone #iPad #Mac #Safari #iLeakage

  5. : Browser-based Timerless Speculative Execution Attacks on Devices :apple_inc:

    ileakage.com/

  6. "🚨 iLeakage: Safari's Side Channel Vulnerability Exposed! 🍎🔓"

    Researchers have unveiled a new attack, dubbed "iLeakage", that exploits a side channel vulnerability in Apple's A- and M-series CPUs. This attack forces Apple’s Safari browser on iOS and macOS devices to reveal passwords, Gmail content, and more. The exploit is practical and doesn't require vast resources but demands in-depth reverse-engineering of Apple hardware. The side channel exploited is speculative execution, a feature in modern CPUs that has been the foundation for numerous attacks recently. The iLeakage attack, when executed, can recover YouTube viewing history, Gmail inbox content, and even passwords autofilled by credential managers. Apple is aware and plans to address this in an upcoming software release. 🚀🔍

    Source: Ars Technica

    Author: Dan Goodin - Senior Security Editor at Ars Technica. Profile

    Tags: #iLeakage #Apple #Safari #SideChannel #Vulnerability #CyberSecurity #iOS #macOS #SpeculativeExecution 🌐🔐🍏

  7. Über eine manipuliserte Webseite lassens ich Passwörter und andere sensible Daten von #Apple-Systemen stehlen. Ausgangspunkt auch hier: Ein Seitenkanal-Angriff auf den Prozessor. #iLeakage winfuture.de/news,139205.html?

  8. #ileakage is a fine example of why browser diversity is important for a healthy web ecosystem.

  9. Hackers can force #iOS and #macOS browsers to divulge passwords and much more
    Researchers devised an attack that forces #Apple’s #Safari browser to divulge #passwords, Gmail message content, and other secrets by exploiting a side channel #vulnerability in A- and M-series CPU running modern iOS and macOS devices dubbed #iLeakage. The side channel in this case is #speculativeexecution, a performance enhancement feature in modern #CPU that formed the basis of many attacks arstechnica.com/security/2023/

  10. So glad #Apple only allows WebKit on the iPhone.... oh wait.

    "While #iLeakage works against Macs only when running Safari, iPhones and iPads can be attacked when running any browser because they’re all based on Apple’s WebKit browser engine."