Article 5JCJA Covert channel in Apple’s M1 is mostly harmless, but it sure is interesting

Covert channel in Apple’s M1 is mostly harmless, but it sure is interesting

by
Dan Goodin
from Ars Technica - All content on (#5JCJA)
Screen-Shot-2020-11-10-at-12.07.08-PM-80

Enlarge (credit: Apple)

Apple's new M1 CPU has a flaw that creates a covert channel that two or more malicious apps-already installed-can use to transmit information to each other, a developer has found.

The surreptitious communication can occur without using computer memory, sockets, files, or any other operating system feature, developer Hector Martin said. The channel can bridge processes running as different users and under different privilege levels. These characteristics allow for the apps to exchange data in a way that can't be detected-or at least without specialized equipment.

Technically, it's a vulnerability but...

Martin said that the flaw is mainly harmless because it can't be used to infect a Mac and it can't be used by exploits or malware to steal or tamper with data stored on a machine. Rather, the flaw can be abused only by two or more malicious apps that have already been installed on a Mac through means unrelated to the M1 flaw.

Read 14 remaining paragraphs | Comments

index?i=CHimRhlT1v0:gKydrPsuBU0:V_sGLiPB index?i=CHimRhlT1v0:gKydrPsuBU0:F7zBnMyn index?d=qj6IDK7rITs index?d=yIl2AUoC8zA
External Content
Source RSS or Atom Feed
Feed Location http://feeds.arstechnica.com/arstechnica/index
Feed Title Ars Technica - All content
Feed Link https://arstechnica.com/
Reply 0 comments