ZeroSecurity - Information Security News
  • Home
  • Security
    • Exploits
    • Mobile Security
  • Malware
  • Breaches
  • Crypto
  • Privacy
  • Tech
    • AI
    • Downloads
      • Malwarebytes
      • Exploits
      • Paper Downloads
    • Reviews
No Result
View All Result
SUBSCRIBE
ZeroSecurity - Information Security News
  • Home
  • Security
    • Exploits
    • Mobile Security
  • Malware
  • Breaches
  • Crypto
  • Privacy
  • Tech
    • AI
    • Downloads
      • Malwarebytes
      • Exploits
      • Paper Downloads
    • Reviews
No Result
View All Result
ZeroSecurity - Information Security News
No Result
View All Result
Home Mobile Security

Implications of iLeakage: Breaching Apple’s Safari Browser for Sensitive Data Theft

Kyle by Kyle
October 29, 2023
in Mobile Security
Reading Time: 3 mins read
apple safari browser bug leak browsing activity showcase
Share on FacebookShare on Twitter

A group of cybersecurity experts, including Daniel Genkin and Jason Kim from Georgia Tech, Stephan van Schaik from the University of Michigan, and Yuval Yarom from Ruhr University Bochum, has published a research paper uncovering a critical vulnerability in Apple devices, affecting both Macs and iPhones.

Termed “iLeakage: Browser-based Timerless Speculative Execution Attacks on Apple Devices,” the vulnerability, known as iLeakage, has silently plagued Apple devices since 2020. This flaw predominantly impacts devices featuring Apple’s Arm-based A-series and M-series chips.

In their research, the team devised an attack that manipulates Apple’s Safari browser to divulge sensitive data, including passwords and Gmail content, by exploiting a side-channel vulnerability within the CPUs.

iLeakage is an offshoot of a long-standing CPU attack technique. In 2018, security researchers revealed that virtually all modern CPUs could be exploited to leak sensitive data by taking advantage of a key CPU feature called Speculative Execution. In this approach, modern CPUs aim to enhance performance by executing instructions ahead of their actual need. iLeakage exploits a timerless speculative execution flaw unique to Apple devices, allowing the CPU to execute instructions in the absence of time constraints. Attackers can harness this to conduct malicious activities without detection.

The core of an iLeakage attack involves tricking the CPU into executing speculative code, accessing sensitive data from memory, and surreptitiously exfiltrating it. Notably, this attack doesn’t necessitate user interaction, such as clicking on malicious links or opening compromised documents, making it particularly insidious.

The vulnerability resides in the way the Safari browser manages JavaScript timers, enabling attackers to craft malicious JavaScript code to pilfer critical data. The stolen information encompasses passwords, personal identification details (PII), and credit card numbers. Such ill-gotten data could be leveraged for nefarious purposes like identity theft and fraud.

iLeakage attacks are presently effective on Apple devices using Safari. However, it remains plausible that other platforms or browsers may harbor similar vulnerabilities. Therefore, users are urged to exercise vigilance by keeping their software updated and deploying security solutions capable of detecting and thwarting speculative execution attacks.

The research findings were responsibly disclosed to Apple on September 12, 2022. Apple acknowledged the issue and collaborated with the researchers to develop countermeasures. As a result, Apple has restructured Safari’s multi-process architecture. These modifications are actively in development and accessible in Safari Technology Preview versions 173 and above.

Apple has also introduced a new inter-process communication API to spawn processes for pages launched with window.open(). This patch has been verified to mitigate iLeakage attacks by preventing domain consolidation across security boundaries, though it has certain limitations.

For in-depth details, the complete report can be accessed here, and a dedicated site is available for demonstrating the iLeakage attack.

https://ileakage.com/files/ileakage-demo-1.mp4
https://ileakage.com/files/ileakage-demo-2.mp4
https://ileakage.com/files/ileakage-demo-3.mp4

Lionel Litty, Chief Security Architect at Menlo Security in Mountain View, California, a browser security provider, emphasized that this attack underscores a paradigm shift where browsers become the new operating system. He noted that web primitives, like origins and web workers, mirror OS primitives, such as applications and threads, making it essential for security professionals to familiarize themselves with this evolving attack surface.

You might also like

How Hackers Still Manage to Compromise MFA

BadBox Botnet Infects Over 190,000 Android Devices Worldwide

Massive Backdoor Infection Hits 1.3 Million Android-Based Streaming Devices

John Gallagher, Vice President of Viakoo Labs at Viakoo, a Mountain View-based automated IoT cyber hygiene provider, highlighted the evolving nature of threats, underscoring that the attack method itself isn’t as significant as the broader trend of threats adapting in response to the trade-off between speed and security. Gallagher pointed out that prefetching information to accelerate CPU execution has been exploited before, making this development part of a larger cycle.

However, Gallagher reassured that organizations are not at high risk from this particular attack, as it demands a high level of sophistication from threat actors, and no instances of it being exploited in the wild have been reported. He advised that organizations, especially high-value targets, consider activating lockdown mode or using available MacOS patches as precautionary measures.

Tags: appleIOSsafari
Previous Post

HackerOne Surpasses $300 Million in Rewards for Ethical Hackers

Next Post

Sharp Surge in QR Code Phishing Attacks Revealed by Check Point

Kyle

Kyle

Writer, and editor at ZeroSecurity. Interested in Information Security, the Blockchain, and an overall tech enthusiast. "Formal education will make you a living; self-education will make you a fortune." Contact me here: [email protected]

Recommended For You

How Hackers Still Manage to Compromise MFA

How Hackers Still Manage to Compromise MFA

March 6, 2026
Discover how the BadBox botnet infects 190,000+ Android devices, compromising smart TVs and smartphones across multiple countries with dangerous malware.

BadBox Botnet Infects Over 190,000 Android Devices Worldwide

December 20, 2024

Massive Backdoor Infection Hits 1.3 Million Android-Based Streaming Devices

September 16, 2024

Cybercriminals Target Mobile Users in the Czech Republic with Phishing Campaigns Leveraging Progressive Web Applications

August 20, 2024

LianSpy: New Android Spyware Targeting Russian Users

August 7, 2024

New Mandrake Android Malware Variant Evades Detection on Google Play

July 29, 2024

Related News

Malicious Chrome Extensions Steal AI Data and Hijack Revenue in DarkSpectre Campaign

Malicious Chrome Extensions Steal AI Data and Hijack Revenue in DarkSpectre Campaign

January 30, 2026
KPMG Netherlands Listed as Victim by Nova Ransomware Group

KPMG Netherlands Listed as Victim by Nova Ransomware Group

January 24, 2026
RansomHouse Claims Breach of Key Apple Assembler Luxshare

RansomHouse Claims Breach of Key Apple Assembler Luxshare

January 20, 2026
ZeroSecurity - Information Security News

We cover the latest in technology news, Crypto, Artificial Intelligence, and the threat trends impacting these sectors.

Categories

Piracy

Tutorials

Programming

Malware Analysis

Downloads

  • Contact us
  • Press
  • Writers
  • Privacy Policy
  • Terms of Service

© 2026 ZeroSecurity, All Rights Reserved.

No Result
View All Result
  • Home
  • Security
    • Tools
  • Exploits
  • Data Breaches
  • Malware
  • Privacy
  • Mobile Security
  • Contact Us
    • Press
  • Privacy Policy

© 2026 ZeroSecurity, All Rights Reserved.

This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.