Skip to main content
  1. Home
  2. Computing
  3. Apple
  4. News

Apple’s M1 chip has a flaw, but you shouldn’t worry

Add as a preferred source on Google

Apple’s M1 chip has revitalized its Mac lineup, but a developer has discovered a flaw they say is “baked into Apple Silicon chips, and cannot be fixed without a new silicon revision.” There is probably no need to worry, though, as the same researcher says the impact of this flaw is negligible.

The exploit allows two apps to pass data between them without the use of files, memory, or any of the other regular ways data is exchanged in an operating system, says Hector Martin, the developer who found the flaw. It can even pass things between users and across privilege levels.

Recommended Videos

Martin warns that this defect is part of all Apple Silicon chips and cannot be remedied without Apple addressing the issue in future silicon designs. In other words, Apple cannot simply release a patch or get users to update their Macs to fix things. And since iPhone chips are also based on Apple Silicon, they too are affected (although Apple’s App Store should snuff out apps that use this exploit automatically, says Martin).

No need to panic

Still, Martin is careful to explain that the risks to ordinary users are minimal. In a Q&A section on his website dedicated to the exploit, Martin outlines exactly what it can and cannot do:

Can malware use this vulnerability to take over my computer?
No.

Can malware use this vulnerability to steal my private information?
No.

Can malware use this vulnerability to rickroll me?
Yes. I mean, it could also rickroll you without using it.

Can this be exploited from JavaScript on a website?
No.

So, what can it be used to do? Advertising companies could potentially use this to bypass Apple’s cross-app tracking protections, but that is about it, says Martin. He is blunt about its malicious uses: “Really, nobody’s going to actually find a nefarious use for this flaw in practical circumstances.”

In fact, Martin says the whole purpose of his website is to “[Poke] fun at how ridiculous infosec clickbait vulnerability reporting has become lately. Just because it has a flashy website or it makes the news doesn’t mean you need to care.”

So if you have an M1 Mac, there is no need to panic. Apple is aware of the bug and is likely working on a fix, but it is unlikely this exploit will cause any sort of widespread disruption. As Martin explains, bad actors have plenty of other, more efficient ways to cause trouble. Getting an antivirus app on your Mac and exercising good common sense will go a long way to keeping you protected.

Alex Blake
Alex Blake has been working with Digital Trends since 2019, where he spends most of his time writing about Mac computers…
Gemini Notebook’s latest update makes it a better study companion
Google is adding voice conversations, lecture recording, interactive quizzes, and short video overviews to its AI-powered notebook.
Gemini Notebook update for students

Google is giving Gemini Notebook, formerly NotebookLM, a major upgrade for students, adding new features designed to help them understand difficult concepts, capture lectures, and turn study materials into interactive learning tools. The update lands alongside a free year of Google's paid AI plan for eligible college students.

Gemini Notebook can now talk you through your notes

Read more
LG 39GX950B review: An ultrawide OLED that gets remarkably close to having it all
LG’s 39-inch 5K2K OLED combines high-end picture quality with seriously fast gaming
Electronics, Screen, Computer Hardware

see at bestbuy

Quick Verdict

Read more
Should we feel bad about deleting an AI? One expert says it’s time to find out
If AI can learn, remember, and make increasingly complex decisions, one expert thinks we should be more careful about how we say goodbye.
an on off toggle

Turning off an AI might sound as simple as hitting a switch, but according to futurist and University of Technology Sydney professor Rocky Scopelliti, that mindset needs to change fast. As first reported by TechXplore, Scopelliti's new book, The Conscious Code, Scopelliti argues that as AI systems get better at reflecting on their own choices, deleting them without a second thought could actually cause harm.

He's not asking us to hand robots legal rights. Instead, he wants us to accept what he calls a duty of good stewardship, basically treating AI responsibly because we're the ones holding the power, not because the AI is demanding it. As he puts it, our design choices can quietly cause damage by wiping out an AI's "learned moral dispositions" without warning.

Read more