{"id":1196244,"date":"2023-10-25T13:00:39","date_gmt":"2023-10-25T17:00:39","guid":{"rendered":"https:\/\/www.prime-wow.com\/?p=1196244"},"modified":"2023-10-25T13:00:39","modified_gmt":"2023-10-25T17:00:39","slug":"hackers-can-force-ios-and-macos-browsers-to-divulge-passwords-and-much-more","status":"publish","type":"post","link":"https:\/\/www.prime-wow.com\/?p=1196244","title":{"rendered":"Hackers can force iOS and macOS browsers to divulge passwords and much more"},"content":{"rendered":"<div id=\"rss-wrap\">\n<figure class=\"intro-image intro-left\">\n  <img decoding=\"async\" src=\"https:\/\/www.prime-wow.com\/wp-content\/uploads\/2023\/10\/ileakage-password-demo-800x451-1.jpg\" alt=\"Hackers can force iOS and macOS browsers to divulge passwords and much more\" \/><\/p>\n<p class=\"caption\" style=\"font-size:0.8em\"><a href=\"https:\/\/cdn.arstechnica.net\/wp-content\/uploads\/2023\/10\/ileakage-password-demo.jpg\" class=\"enlarge-link\" data-height=\"905\" data-width=\"1604\">Enlarge<\/a> (credit: Kim et al.)<\/p>\n<\/figure>\n<div><a name=\"page-1\" \/><\/div>\n<p>Researchers have devised an attack that forces Apple\u2019s Safari browser to divulge passwords, Gmail message content, and other secrets by exploiting a side channel vulnerability in the A- and M-series CPUs running modern iOS and macOS devices.<\/p>\n<p>iLeakage, as the academic researchers have named the attack, is practical and requires minimal resources to carry out. It does, however, require extensive reverse-engineering of Apple hardware and significant expertise in exploiting a class of vulnerability known as a <a href=\"https:\/\/en.wikipedia.org\/wiki\/Side-channel_attack\">side channel<\/a>, which leaks secrets based on clues left in electromagnetic emanations, data caches, or other manifestations of a targeted system. The side channel in this case is speculative execution, a performance enhancement feature found in modern CPUs that has formed the basis of a <a href=\"https:\/\/arstechnica.com\/gadgets\/2021\/05\/new-spectre-attack-once-again-sends-intel-and-amd-scrambling-for-a-fix\/\">wide<\/a> <a href=\"https:\/\/arstechnica.com\/gadgets\/2018\/01\/meltdown-and-spectre-every-modern-processor-has-unfixable-security-flaws\/\">corpus<\/a> of <a href=\"https:\/\/arstechnica.com\/information-technology\/2020\/03\/hackers-can-steal-secret-data-stored-in-intels-sgx-secure-enclave\/\">attacks<\/a> in <a href=\"https:\/\/arstechnica.com\/information-technology\/2020\/06\/new-exploits-plunder-crypto-keys-and-more-from-intels-ultrasecure-sgx\/\">recent<\/a> years. The nearly endless stream of exploit variants has left chip makers\u2014primarily Intel and, to a lesser extent, AMD\u2014scrambling to devise mitigations.<\/p>\n<h2>Exploiting WebKit on Apple silicon<\/h2>\n<p>The researchers implement iLeakage as a website. When visited by a vulnerable macOS or iOS device, the website uses JavaScript to surreptitiously open a separate website of the attacker\u2019s choice and recover site content rendered in a pop-up window. The researchers have successfully leveraged iLeakage to recover YouTube viewing history, the content of a Gmail inbox\u2014when a target is logged in\u2014and a password as it\u2019s being autofilled by a credential manager. Once visited, the iLeakage site requires about five minutes to profile the target machine and, on average, roughly another 30 seconds to extract a 512-bit secret, such as a 64-character string.<\/p>\n<\/div>\n<p><a href=\"https:\/\/arstechnica.com\/?p=1978389#p3\">Read 18 remaining paragraphs<\/a> | <a href=\"https:\/\/arstechnica.com\/?p=1978389&amp;comments=1\">Comments<\/a><\/p>\n<p>&#013;<br \/>\n&#013;<br \/>\nSource: Ars Technica &#8211; <a href=\"https:\/\/arstechnica.com\/?p=1978389\" target=\"_blank\" rel=\"noopener\">Hackers can force iOS and macOS browsers to divulge passwords and much more<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Enlarge (credit: Kim et al.) Researchers have devised an attack that forces Apple\u2019s Safari browser to divulge passwords, Gmail message content, and other secrets by exploiting a side channel vulnerability in the A- and M-series CPUs running modern iOS and &hellip; <a href=\"https:\/\/www.prime-wow.com\/?p=1196244\">Continue reading <span class=\"meta-nav\">&rarr;<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":1196245,"comment_status":"open","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[27,110],"tags":[73],"class_list":["post-1196244","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-ars-technica","category-unfiltered-rss","tag-ars-technica"],"_links":{"self":[{"href":"https:\/\/www.prime-wow.com\/index.php?rest_route=\/wp\/v2\/posts\/1196244","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.prime-wow.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.prime-wow.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.prime-wow.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.prime-wow.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=1196244"}],"version-history":[{"count":0,"href":"https:\/\/www.prime-wow.com\/index.php?rest_route=\/wp\/v2\/posts\/1196244\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.prime-wow.com\/index.php?rest_route=\/wp\/v2\/media\/1196245"}],"wp:attachment":[{"href":"https:\/\/www.prime-wow.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=1196244"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.prime-wow.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=1196244"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.prime-wow.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=1196244"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}