New iLeakage attack can steal your emails and passwords on iPhone and Mac — how to stay safe (2024)

New iLeakage attack can steal your emails and passwords on iPhone and Mac — how to stay safe (1)

If you thought your iPhone and Mac were safe from hackers, think again. Academic researchers have developed a new attack method that can steal sensitive data from anyone using Safari on their Apple devices.

As reported by BleepingComputer, this new side-channel attack has been given the name iLeakage by a team of researchers from Georgia Tech, University of Michigan and Ruhr University Bochum. When launched on a vulnerable Apple device, this attack can be used to steal emails, passwords, and other important data right from Safari. However, it also works on Firefox, Tor, and Edge on iOS.

What makes iLeakage particularly worrying is that it affects the best iPhones, as well as the best MacBooks using Apple Silicon. This means that newer Macs running M1, M2 and potentially even Apple’s upcoming M3 chips are impacted.

While iLeakage was developed by academic researchers, and shares a lot of similarities with 2018’s Spectre attacks which affect Intel CPUs, it currently isn’t being used in the wild by hackers in their attacks. However, now that we know Apple Silicon is vulnerable to this type of attack, hackers could develop their own implementation of iLeakage or create a similar attack method in the future.

Stealing emails and passwords from Apple devices

As iLeakage is a novel attack method, it’s quite complicated and you can see all the details in this research paper (PDF) written by the team that developed it.

Essentially, the attack works by forcing Safari to render an arbitrary webpage and then sensitive information within it is recovered using speculative execution. The researchers managed to do this by overcoming the side-channel protections — like the low-resolution timer, compressed 35-bit addressing and value poisoning — that Apple has implemented in Safari.

They also employed speculative type confusion to bypass these restrictions, and this allowed them to leak sensitive data such as emails and passwords from a targeted page. In a series of YouTube videos (Demo 1, Demo 2, Demo 3), the researchers showed how they were able to steal Gmail messages as well as retrieve a password from an Instagram test account that was auto-filled in Safari using LastPass.

From here, they took things a step further by demonstrating how iLeakage attacks also work on Chrome for iOS. This is possible because Apple’s policy requires all third-party browsers for iOS to actually be overlays running on top of Safari which uses its JavaScript engine.

While Apple has yet to formally comment on these new iLeakage attacks, in an email to Tom’s Guide, an Apple spokesperson revealed the company is aware of the issue and that it will be addressed in its next scheduled software release.

How to stay safe from iLeakage

New iLeakage attack can steal your emails and passwords on iPhone and Mac — how to stay safe (2)

All Apple devices released from 2020 onwards that use either the company’s A-Series or M-Series ARM processors are impacted by iLeakage. Since this attack is essentially undetectable, as it leaves no trace on a victim’s devices, you may be wondering what you can do to stay safe.

Fortunately, the researchers behind iLeakage privately disclosed this new attack to Apple back in September of last year and the company developed mitigations for macOS. It’s worth noting that the researchers say that this attack is difficult to carry out since advanced knowledge of browser-based side-channel attacks, and Safari’s implementation are required to do so. Still though, if you’re worried, here are some steps you can take to keep your Mac safe if you’re running macOS Ventura 13.0 or higher.

To start, open Terminal on your Mac and run “defaults write com.apple.Safari IncludeInternalDebugMenu 1” to enable Safari’s hidden debug menu. Now when you open Safari, its Debug menu will be visible and you can use it to open the “WebKit Internal Features” setting. When scrolling through this menu, you need to activate “Swap Processes on Cross-Site Window Open." While this will protect you, it could introduce some stability issues on your Mac. For this reason, you might want to hold off on doing this and wait for Apple to formally address iLeakage in its next major software update.

As for protecting your Mac from malware and other viruses, you should also consider installing the best Mac antivirus software as well. Likewise, Intego Mac Internet Security X9 and Intego Mac Premium Bundle X9 can scan your iPhone or iPad for malware but they need to be plugged into your Mac using a USB cable to do so.

Unlike zero-day flaws that are often used by hackers in their attacks, iLeakage is a proof of concept which shows that Apple Silicon is vulnerable to side-channel attacks just like processors from Intel, AMD and other chip makers. We could potentially find out more in the future but this won’t happen until a fix for iLeakage is rolled out and even then, Apple tends to play things close to the chest regarding vulnerabilities and new attack methods.

More from Tom's Guide

  • Macs under threat from malicious ads spreading malware — don’t fall for this
  • Intel-based Macs under attack from new MetaStealer malware
  • Google will soon hide your IP address in Chrome to protect your privacy

Anthony Spadafora

Senior Editor Security and Networking

Anthony Spadafora is the security and networking editor at Tom’s Guide where he covers everything from data breaches and ransomware gangs to password managers and the best way to cover your whole home or business with Wi-Fi. Before joining the team, he wrote for ITProPortal while living in Korea and later for TechRadar Pro after moving back to the US. Based in Houston, Texas, when he’s not writing Anthony can be found tinkering with PCs and game consoles, managing cables and upgrading his smart home.

More about iphones

iPhone 16 Pro Max leak just revealed advantage over Galaxy S24 Ultra and Pixel 9 Pro XLiPhone 16 and iPhone 16 Pro prices — will Apple give us a price hike?

Latest

Samsung's new 4K gaming monitor offers glasses-free 3D — it's a game-changer
See more latest►

No comments yetComment from the forums

    Most Popular
    Samsung Galaxy Z Fold 6 Slim might be the first foldable with titanium
    The best thriller movie of the summer just got a streaming release date — and it's very soon
    Google Pixel 9 performance looks disappointing after Tensor G4 benchmark results leak
    The one crime thriller show you haven't watched just crashed Netflix's top 10 — and it's 100% on Rotten Tomatoes
    iPhone 16 Pro Max leak just revealed advantage over Galaxy S24 Ultra and Pixel 9 Pro XL
    Google Pixel 9 makes transferring data from your old phone easy — even after it’s set up
    5 best classics just added to Prime Video with 90% or higher on Rotten Tomatoes
    Garmin Fenix 8: All the rumors so far
    This new TV accessory lets you smell what’s on the screen (Hint: it’s not pleasant)
    Can't keep your air fryer clean? These 5 foods could be the culprit
    NordVPN takes a podium position in test exposing fake online stores
    New iLeakage attack can steal your emails and passwords on iPhone and Mac — how to stay safe (2024)
    Top Articles
    MidFirst Bank Review | SmartAsset.com
    MidFirst Bank on LinkedIn: #midfirstbank #truetoyou
    The Tribes and Castes of the Central Provinces of India, Volume 3
    Ups Customer Center Locations
    Don Wallence Auto Sales Vehicles
    Brgeneral Patient Portal
    Bloxburg Image Ids
    270 West Michigan residents receive expert driver’s license restoration advice at last major Road to Restoration Clinic of the year
    Babyrainbow Private
    United Dual Complete Providers
    Huge Boobs Images
    Arboristsite Forum Chainsaw
    Minecraft Jar Google Drive
    Munich residents spend the most online for food
    Used Sawmill For Sale - Craigslist Near Tennessee
    Adam4Adam Discount Codes
    Accuweather Mold Count
    Scotchlas Funeral Home Obituaries
    Concordia Apartment 34 Tarkov
    Glenda Mitchell Law Firm: Law Firm Profile
    Terry Bradshaw | Biography, Stats, & Facts
    Wics News Springfield Il
    Yugen Manga Jinx Cap 19
    Target Minute Clinic Hours
    Ticket To Paradise Showtimes Near Cinemark Mall Del Norte
    CVS Health’s MinuteClinic Introduces New Virtual Care Offering
    Carroway Funeral Home Obituaries Lufkin
    They Cloned Tyrone Showtimes Near Showbiz Cinemas - Kingwood
    Valley Craigslist
    Basil Martusevich
    L'alternativa - co*cktail Bar On The Pier
    Moonrise Time Tonight Near Me
    #scandalous stars | astrognossienne
    Lichen - 1.17.0 - Gemsbok! Antler Windchimes! Shoji Screens!
    Polk County Released Inmates
    Studio 22 Nashville Review
    10 games with New Game Plus modes so good you simply have to play them twice
    Rhode Island High School Sports News & Headlines| Providence Journal
    Lcwc 911 Live Incident List Live Status
    Ferguson Showroom West Chester Pa
    Lima Crime Stoppers
    Engr 2300 Osu
    Cnp Tx Venmo
    ESA Science & Technology - The remarkable Red Rectangle: A stairway to heaven? [heic0408]
    The Cutest Photos of Enrique Iglesias and Anna Kournikova with Their Three Kids
    6463896344
    Dolce Luna Italian Restaurant & Pizzeria
    116 Cubic Inches To Cc
    Poster & 1600 Autocollants créatifs | Activité facile et ludique | Poppik Stickers
    Deshuesadero El Pulpo
    Ark Silica Pearls Gfi
    Gainswave Review Forum
    Latest Posts
    Article information

    Author: Lidia Grady

    Last Updated:

    Views: 6169

    Rating: 4.4 / 5 (65 voted)

    Reviews: 88% of readers found this page helpful

    Author information

    Name: Lidia Grady

    Birthday: 1992-01-22

    Address: Suite 493 356 Dale Fall, New Wanda, RI 52485

    Phone: +29914464387516

    Job: Customer Engineer

    Hobby: Cryptography, Writing, Dowsing, Stand-up comedy, Calligraphy, Web surfing, Ghost hunting

    Introduction: My name is Lidia Grady, I am a thankful, fine, glamorous, lucky, lively, pleasant, shiny person who loves writing and wants to share my knowledge and understanding with you.