Skip to main content

Apple’s M1 chip has a flaw, but you shouldn’t worry

Apple’s M1 chip has revitalized its Mac lineup, but a developer has discovered a flaw they say is “baked into Apple Silicon chips, and cannot be fixed without a new silicon revision.” There is probably no need to worry, though, as the same researcher says the impact of this flaw is negligible.

The exploit allows two apps to pass data between them without the use of files, memory, or any of the other regular ways data is exchanged in an operating system, says Hector Martin, the developer who found the flaw. It can even pass things between users and across privilege levels.

Martin warns that this defect is part of all Apple Silicon chips and cannot be remedied without Apple addressing the issue in future silicon designs. In other words, Apple cannot simply release a patch or get users to update their Macs to fix things. And since iPhone chips are also based on Apple Silicon, they too are affected (although Apple’s App Store should snuff out apps that use this exploit automatically, says Martin).

No need to panic

Still, Martin is careful to explain that the risks to ordinary users are minimal. In a Q&A section on his website dedicated to the exploit, Martin outlines exactly what it can and cannot do:

Can malware use this vulnerability to take over my computer?

Can malware use this vulnerability to steal my private information?

Can malware use this vulnerability to rickroll me?
Yes. I mean, it could also rickroll you without using it.

Can this be exploited from JavaScript on a website?

So, what can it be used to do? Advertising companies could potentially use this to bypass Apple’s cross-app tracking protections, but that is about it, says Martin. He is blunt about its malicious uses: “Really, nobody’s going to actually find a nefarious use for this flaw in practical circumstances.”

In fact, Martin says the whole purpose of his website is to “[Poke] fun at how ridiculous infosec clickbait vulnerability reporting has become lately. Just because it has a flashy website or it makes the news doesn’t mean you need to care.”

So if you have an M1 Mac, there is no need to panic. Apple is aware of the bug and is likely working on a fix, but it is unlikely this exploit will cause any sort of widespread disruption. As Martin explains, bad actors have plenty of other, more efficient ways to cause trouble. Getting an antivirus app on your Mac and exercising good common sense will go a long way to keeping you protected.

Editors' Recommendations

Alex Blake
In ancient times, people like Alex would have been shunned for their nerdy ways and strange opinions on cheese. Today, he…
Got an M1 Mac? Apple will now let you repair it yourself
A person repairing a MacBook using Apple's self-service repair kit.

Apple has expanded its self-service repair program to include a new slate of desktop Macs, as spotted by Six Colors. The move has increased the number of people eligible to get hands-on and fix their Apple computers at home using official components and guides. Previously, only a handful of MacBooks qualified for the program.

The devices freshly inducted into the program include the M1 iMac, M1 Mac mini, the Mac Studio, and the Studio Display. Owners of these Macs and displays will now get access to official parts and manuals to help them fix up their products without needing to go to an Apple Store or a third-party repair shop.

Read more
I’m still waiting for Apple to fix the Mac Mini’s major problem
The M1-powered Mac Mini.

As a desktop machine, my M1 Mac Mini is absolutely great. It’s small enough to pop into a backpack, but capable enough to handle my workloads with ease. Yet there’s one problem nagging at me that makes me worried for the future of the Mac Mini line -- and it likely won’t be fixed any time soon.

That’s because, while the Mac Mini is ideal for most of my work, there are times when I wish it had a bit more power. That doesn’t come up often -- it’s mainly when I’m playing and reviewing Mac games. I’ll often have to turn the settings down lower than I’d like, which is perhaps unsurprising given that the M1’s integrated graphics were part of Apple’s first stab at its own desktop chip.

Read more
Apple’s M2 Max chip may bring next-level performance to the MacBook Pro
An Apple M2 chip on a stylized gradient background.

Apple's M2 Max chip is not out yet, but some benchmarks of it already are. One such test was leaked today, showing off the performance of the new processor.

According to these scores, we might see a decent performance boost in the future MacBook Pros that will likely come with the M2 Max chip. Of course, things can still improve.

Read more