HT TECH wants to start sending you push notifications. Click allow to subscribe

Researcher uncovers flaw on M1 chips, but you probably shouldn't be worried

The M1RACLES bug reportedly allows one process to talk to another, bypassing the operating system's security model that prevents such cross-talk.

By: HT TECH
Updated on: Aug 21 2022, 17:31 IST
MacBook. (Unsplash)

When Apple launched its brand new in-house ARM-based M1 chip last year, the company last year, it touted the chip’s capable performance as well as improved security over its predecessors and existing rivals in the industry. However, no computer system is completely secure and devoid of flaws, and Apple’s new chipset is no exception. A developer has discovered a vulnerability in the processor’s hardware that cannot be patched via a software update.

According to The Register, Linux developer Hector Martin found a new vulnerability in the M1 chipset, which he has called M1RACLES, or M1ssing Register Access Controls Leak EL0 State. The flaw allows one process running on a system powered by Apple’s chipset to talk to another process, bypassing the operating system's security model that prevents such cross-talk.

You may be interested in

Laptops Tablets
Apple MacBook Pro M1 Max MK1A3HN A Ultrabook
  • Space Grey
  • 32 GB RAM
  • 1 TB SSD
₹319,900
Buy now
Apple MacBook Pro MV972HN A Ultrabook
  • Space Grey
  • 8 GB RAM
  • 512 GB SSD
₹134,900
Buy now
Apple MacBook Air MRE92HN A Ultrabook
  • Space Grey
  • 8 GB RAM
  • 256 GB SSD
₹134,900
Buy now
Apple MacBook Pro M2 MNEH3HN A Ultrabook
  • Space Grey
  • 8 GB RAM
  • 256 GB SSD
₹100,000
Buy now
3% OFF
Apple iPad Pro 12 9 2022 WiFi plus Cellular 512GB
  • Silver
  • 8 GB RAM
  • 512 GB Storage
₹153,100₹157,900
Buy now
3% OFF
Apple iPad Pro 11 2022 WiFi 1TB
  • Silver
  • 16 GB RAM
  • 1 TB Storage
₹147,328₹151,900
Buy now
Apple iPad Pro 11 2022 WiFi plus Cellular 512GB
  • Silver
  • 8 GB RAM
  • 512 GB Storage
₹126,900
Buy now
3% OFF
Apple iPad 10 9 2022 WiFi plus Cellular 256GB
  • Blue
  • 256 GB Storage
₹72,499₹74,900
Buy now

Also read: Apple’s software chief faults Mac security to keep grip on iPhone App Store

This kind of vulnerability is used by malicious actors in what is called a side-channel attack, by taking advantage of the information that can be leaked in the process. Normally, an operating system will restrict communication between processes to ensure the security of the data being processed by either side, such as passwords or authentication keys.

However, Martin says that while the security vulnerability is due to the way Apple has designed the chip, there’s not much that can be done in terms of a software fix. According to him, the flaw affects systems running macOS Big Sur (which was designed to run on the M1 chip), iOS and iPadOS, as well as Linux distributions on kernel version 5.13 and higher.

"Basically, Apple decided to break the ARM spec by removing a mandatory feature, because they figured they'd never need to use that feature for macOS. And then it turned out that removing that feature made it much harder for existing OSes to mitigate this vulnerability," Martin says on the disclosure website

He claims that he mailed Apple about the security flaw and that the company acknowledged the vulnerability and assigned it CVE-2021-30747. He states that he published the disclosure on the website 90 days after the initial disclosure to the company.

Read more: Apple fixes security flaws in seven-year-old iPhone models with iOS 12.5.3

“Really, nobody's going to actually find a nefarious use for this flaw in practical circumstances. Besides, there are already a million side channels you can use for cooperative cross-process communication (e.g. cache stuff), on every system. Covert channels can't leak data from uncooperative apps or systems,” Martin explains, adding that users should probably worry about malware, which is a much more dangerous threat than this particular security flaw.  

Catch all the Latest Tech News, Mobile News, Laptop News, Gaming news, Wearables News , How To News, also keep up with us on ,Twitter, Facebook, , and Instagram. For our latest videos, subscribe to our YouTube channel.

First Published Date: 27 May, 23:57 IST
Tags:

Sale

Laptops Tablets
23% OFF
Infinix INBook X1 Neo XL22 Laptop Intel Celeron Quad Core 8 GB 256 GB SSD Windows 11
  • Blue
  • 4 GB RAM
  • 128 GB SSD
₹22,990₹29,990
Buy now
42% OFF
Asus ROG Zephyrus G14 GA401QC HZ046TS Laptop
  • Eclipse Gray
  • 8 GB RAM
  • 1 TB SSD
₹89,990₹155,990
Buy now
39% OFF
Asus TUF Gaming A15 FA566IH HN150TS Laptop
  • Fortress Grey
  • 8 GB RAM
  • 1 TB HDD
₹55,600₹90,990
Buy now
25% OFF
Asus ROG Strix G15 G513QR HQ222TS Laptop
  • Eclipse Grey
  • 16 GB RAM
  • 1 TB SSD
₹86,990₹115,990
Buy now
8% OFF
Apple iPad Air 2020
  • Space Gray
  • 4 GB RAM
  • 64 GB Storage
₹45,999₹49,900
Buy now
4% OFF
Apple iPad Pro 11 WiFi Cellular 512GB
  • Silver
  • 4 GB RAM
  • 512 GB Storage
₹106,999₹111,900
Buy now
9% OFF
Apple iPad Pro 12 9 2021 WiFi plus Cellular 512GB
  • Silver
  • 8 GB RAM
  • 512 GB Storage
₹129,999₹142,900
Buy now
4% OFF
Apple iPad Pro 11 WiFi 512GB
  • Silver
  • 4 GB RAM
  • 512 GB Storage
₹106,999₹111,900
Buy now
NEXT ARTICLE BEGINS