New iLeakage attack can steal your emails and passwords on iPhone and Mac — how to stay safe (2024)

New iLeakage attack can steal your emails and passwords on iPhone and Mac — how to stay safe (1)

If you thought your iPhone and Mac were safe from hackers, think again. Academic researchers have developed a new attack method that can steal sensitive data from anyone using Safari on their Apple devices.

As reported by BleepingComputer, this new side-channel attack has been given the name iLeakage by a team of researchers from Georgia Tech, University of Michigan and Ruhr University Bochum. When launched on a vulnerable Apple device, this attack can be used to steal emails, passwords, and other important data right from Safari. However, it also works on Firefox, Tor, and Edge on iOS.

What makes iLeakage particularly worrying is that it affects the best iPhones, as well as the best MacBooks using Apple Silicon. This means that newer Macs running M1, M2 and potentially even Apple’s upcoming M3 chips are impacted.

While iLeakage was developed by academic researchers, and shares a lot of similarities with 2018’s Spectre attacks which affect Intel CPUs, it currently isn’t being used in the wild by hackers in their attacks. However, now that we know Apple Silicon is vulnerable to this type of attack, hackers could develop their own implementation of iLeakage or create a similar attack method in the future.

Stealing emails and passwords from Apple devices

As iLeakage is a novel attack method, it’s quite complicated and you can see all the details in this research paper (PDF) written by the team that developed it.

Essentially, the attack works by forcing Safari to render an arbitrary webpage and then sensitive information within it is recovered using speculative execution. The researchers managed to do this by overcoming the side-channel protections — like the low-resolution timer, compressed 35-bit addressing and value poisoning — that Apple has implemented in Safari.

They also employed speculative type confusion to bypass these restrictions, and this allowed them to leak sensitive data such as emails and passwords from a targeted page. In a series of YouTube videos (Demo 1, Demo 2, Demo 3), the researchers showed how they were able to steal Gmail messages as well as retrieve a password from an Instagram test account that was auto-filled in Safari using LastPass.

From here, they took things a step further by demonstrating how iLeakage attacks also work on Chrome for iOS. This is possible because Apple’s policy requires all third-party browsers for iOS to actually be overlays running on top of Safari which uses its JavaScript engine.

While Apple has yet to formally comment on these new iLeakage attacks, in an email to Tom’s Guide, an Apple spokesperson revealed the company is aware of the issue and that it will be addressed in its next scheduled software release.

How to stay safe from iLeakage

New iLeakage attack can steal your emails and passwords on iPhone and Mac — how to stay safe (2)

All Apple devices released from 2020 onwards that use either the company’s A-Series or M-Series ARM processors are impacted by iLeakage. Since this attack is essentially undetectable, as it leaves no trace on a victim’s devices, you may be wondering what you can do to stay safe.

Fortunately, the researchers behind iLeakage privately disclosed this new attack to Apple back in September of last year and the company developed mitigations for macOS. It’s worth noting that the researchers say that this attack is difficult to carry out since advanced knowledge of browser-based side-channel attacks, and Safari’s implementation are required to do so. Still though, if you’re worried, here are some steps you can take to keep your Mac safe if you’re running macOS Ventura 13.0 or higher.

To start, open Terminal on your Mac and run “defaults write com.apple.Safari IncludeInternalDebugMenu 1” to enable Safari’s hidden debug menu. Now when you open Safari, its Debug menu will be visible and you can use it to open the “WebKit Internal Features” setting. When scrolling through this menu, you need to activate “Swap Processes on Cross-Site Window Open." While this will protect you, it could introduce some stability issues on your Mac. For this reason, you might want to hold off on doing this and wait for Apple to formally address iLeakage in its next major software update.

As for protecting your Mac from malware and other viruses, you should also consider installing the best Mac antivirus software as well. Likewise, Intego Mac Internet Security X9 and Intego Mac Premium Bundle X9 can scan your iPhone or iPad for malware but they need to be plugged into your Mac using a USB cable to do so.

Unlike zero-day flaws that are often used by hackers in their attacks, iLeakage is a proof of concept which shows that Apple Silicon is vulnerable to side-channel attacks just like processors from Intel, AMD and other chip makers. We could potentially find out more in the future but this won’t happen until a fix for iLeakage is rolled out and even then, Apple tends to play things close to the chest regarding vulnerabilities and new attack methods.

More from Tom's Guide

  • Macs under threat from malicious ads spreading malware — don’t fall for this
  • Intel-based Macs under attack from new MetaStealer malware
  • Google will soon hide your IP address in Chrome to protect your privacy

Anthony Spadafora

Senior Editor Security and Networking

Anthony Spadafora is the security and networking editor at Tom’s Guide where he covers everything from data breaches and ransomware gangs to password managers and the best way to cover your whole home or business with Wi-Fi. Before joining the team, he wrote for ITProPortal while living in Korea and later for TechRadar Pro after moving back to the US. Based in Houston, Texas, when he’s not writing Anthony can be found tinkering with PCs and game consoles, managing cables and upgrading his smart home.

More about iphones

AppleCare+ just got an extension period for updating your plan — what you need to knowiPhone 16 Pro Max leak just revealed advantage over Galaxy S24 Ultra and Pixel 9 Pro XL

Latest

Windows Recall set for a return — when you can expect this controversial feature to appear
See more latest►

No comments yetComment from the forums

    Most Popular
    New Xbox Series X and Series S consoles are launching for the holidays — here's how to pre-order yours right now
    How to watch 'Sherwood' season 2 online from anywhere
    The Sonos app is a mess right now — here's what happened
    Netflix just added my favorite detective show of the year — stream the entire first season now
    Samsung's new 4K gaming monitor offers glasses-free 3D — it's a game-changer
    Google Gemini can now write better emails than you — here's how to use it
    How to watch 'Lie to Fly' online — stream shocking airline pilot documentary from anywhere
    This new controller could be my dream PC and Xbox gamepad — here's why I’m hyped
    Prime Video is about to lose one of the best sci-fi movies ever — and it's 90% on Rotten Tomatoes
    PS5 Pro pre-orders could arrive very soon — here’s why
    Prime Video just teased its new video game TV show with must-watch first trailer — and it looks better than 'Fallout'
    New iLeakage attack can steal your emails and passwords on iPhone and Mac — how to stay safe (2024)
    Top Articles
    avin Resources and nery - [PDF Document]
    DEPARTMENT OF TRANSPORTATION NOTICE TO …apps.sd.gov/HC65C2C/EBS/lettings/specprov/04Q1_SpecProv.pdf · An electronic version of the most recent version of the South Dak ota ... - [PDF Document]
    Safety Jackpot Login
    Regal Amc Near Me
    Citibank Branch Locations In Orlando Florida
    Unity Stuck Reload Script Assemblies
    Teamexpress Login
    O'reilly's In Monroe Georgia
    Heska Ulite
    Ap Chem Unit 8 Progress Check Mcq
    New Mexico Craigslist Cars And Trucks - By Owner
    What is the difference between a T-bill and a T note?
    Viprow Golf
    5 high school volleyball stars of the week: Sept. 17 edition
    Teenleaks Discord
    Icommerce Agent
    Sni 35 Wiring Diagram
    Pinellas Fire Active Calls
    Www Craigslist Com Bakersfield
    Finalize Teams Yahoo Fantasy Football
    Tyrone Unblocked Games Bitlife
    Teen Vogue Video Series
    Tips and Walkthrough: Candy Crush Level 9795
    Ecampus Scps Login
    Baldur's Gate 3: Should You Obey Vlaakith?
    Skycurve Replacement Mat
    Coindraw App
    Doctors of Optometry - Westchester Mall | Trusted Eye Doctors in White Plains, NY
    Goodwill Of Central Iowa Outlet Des Moines Photos
    Expression Home XP-452 | Grand public | Imprimantes jet d'encre | Imprimantes | Produits | Epson France
    Gesichtspflege & Gesichtscreme
    Federal Express Drop Off Center Near Me
    Dairy Queen Lobby Hours
    Bernie Platt, former Cherry Hill mayor and funeral home magnate, has died at 90
    Compress PDF - quick, online, free
    Umiami Sorority Rankings
    Are you ready for some football? Zag Alum Justin Lange Forges Career in NFL
    Fifty Shades Of Gray 123Movies
    Indiana Jones 5 Showtimes Near Cinemark Stroud Mall And Xd
    Metro Pcs Forest City Iowa
    Craigs List Hartford
    Nid Lcms
    814-747-6702
    Random Animal Hybrid Generator Wheel
    How To Customise Mii QR Codes in Tomodachi Life?
    Best Suv In 2010
    Air Sculpt Houston
    Benjamin Franklin - Printer, Junto, Experiments on Electricity
    Mejores páginas para ver deportes gratis y online - VidaBytes
    House For Sale On Trulia
    About us | DELTA Fiber
    Hkx File Compatibility Check Skyrim/Sse
    Latest Posts
    Article information

    Author: Nathanael Baumbach

    Last Updated:

    Views: 5923

    Rating: 4.4 / 5 (75 voted)

    Reviews: 90% of readers found this page helpful

    Author information

    Name: Nathanael Baumbach

    Birthday: 1998-12-02

    Address: Apt. 829 751 Glover View, West Orlando, IN 22436

    Phone: +901025288581

    Job: Internal IT Coordinator

    Hobby: Gunsmithing, Motor sports, Flying, Skiing, Hooping, Lego building, Ice skating

    Introduction: My name is Nathanael Baumbach, I am a fantastic, nice, victorious, brave, healthy, cute, glorious person who loves writing and wants to share my knowledge and understanding with you.