Skip to main content
  1. Home
  2. Computing
  3. News

Apple isn’t addressing hardware threat to M-series Macs

Add as a preferred source on Google
A person running Steam on the M4 MacBook Pro. Rocket League is up on the screen
Chris Hagan / Digital Trends

Security researchers have discovered new security flaws affecting Apple devices with M2 or A15 chips and onwards. This includes iPhones, iPads, Mac laptops, and Mac desktops. The vulnerabilities, dubbed SLAP and FLOP and first reported by Bleeping Computer, could allow attackers to read information from a user’s open web tabs. Depending on the tabs you have open, this could put sensitive data like passwords and banking information at risk. 

This isn’t a software problem, but rather a hardware flaw that affects CPUs and leaves them vulnerable to side channel attacks. This kind of exploit measures CPU activity and uses factors like power consumption, timing, and sound to infer information about the user’s behavior. The Spectre and Meltdown flaws from 2018 worked in a similar way.

Recommended Videos

It’s pretty complicated stuff, but the important part is that it makes it possible for attackers to get their hands on sensitive information even when it’s properly protected by the software your PC is running. The cause of these weaknesses isn’t purely an Apple problem, it’s a performance optimization that’s used on most modern CPUs.

Computer programs are just a long series of instructions that the CPU executes, but because there are so many different outcomes to cover, those instructions expand into all sorts of different branches. “If A then do X, if B then do Y,” or “If A happens, return to point X” — in a large program, millions of decisions like these happen in order to progress. 

To speed things up, it’s now standard practice to predict which path the CPU should take and start executing instructions further down the line. This way, more work can be done at the same time, rather than every instruction waiting for its turn in the proper order. 

This optimization is called speculative execution or branch prediction, and because it’s based on predictions, it doesn’t always go well. It’s when the predictions backfire that we get these hardware vulnerabilities that attackers can take advantage of. 

SLAP and FLOP flaws on Apple Silicon.
predictors.fail / predictors.fail

The full names of the new flaws are “Data Speculation Attacks via Load Address Prediction on Apple Silicon (SLAP)” and “Breaking the Apple M3 CPU via False Load Output Predictions (FLOP).” They both cause essentially the same problem, but while SLAP is limited to the Safari browser, FLOP works with Chrome as well. 

The research proves with demos that attacks based on these flaws are possible, but there’s no evidence of any cybercriminals using them at the moment. The researchers shared their findings with Apple last year and said that the company responded, stating that it plans to address the issues. However, months have passed and since the papers have been published, the only official comment from Apple (to BleepingComputer) is this:

“We want to thank the researchers for their collaboration as this proof of concept advances our understanding of these types of threats. Based on our analysis, we do not believe this issue poses an immediate risk to our users.”

Although these attacks don’t involve malware, they still begin with a visit to a malicious website. As always, the best way to protect yourself until we get security updates is to be careful of suspicious links and URLs while browsing.

Willow Roberts
Willow Roberts has been a Computing Writer at Digital Trends for a year and has been writing for about a decade. She has a…
I didn’t think fake shopping could trick my brain until I tried the viral dopamine websites
On these fake shopping and delivery sites, nothing ever ships or costs a cent, yet the dopamine hit still felt real.
fake-shopping-on-viral-dopamine-websites

I spent some time in the internet's fakest mall, filling a shopping cart with things I could not buy, hunting for discounts on products that do not exist, and checking out three separate times for a grand total of $0.00. Then I placed a fake food order and smoked a cigarette I could not taste, with strangers I will never meet, on a rooftop that does not exist either. My bank balance never changed, but my brain, annoyingly, did.

When I first heard about South Korea's growing "dopamine sites," I assumed they were another internet oddity I would poke around for five minutes and forget by lunch. Instead, I found a surprisingly clever idea hiding beneath the absurdity. You can browse endless imaginary products, add everything to your cart, and complete a purchase that never actually exists. These websites aren't trying to sell you anything. They're trying to recreate the feeling of shopping while removing the part that empties your wallet.

Read more
LG wants to build humanoid robots, and NVIDIA is giving it the brains
This isn't just another robot teaser. LG and NVIDIA just outlined actual hardware.
Robot, Appliance, Device

With time, more and more legacy hardware companies seem to be racing to bolt a humanoid robot onto their roadmap. The latest entrant is LG, joining the race with tentative timelines.

The company's bipedal humanoid, built on Nvidia's robotics stack, is planned for early 2027, and it's backed by a broader push into AI factories and self-driving vehicle platforms.

Read more
Googlebook may use older Snapdragon chips to build more affordable laptops
Snapdragon X Plus and X Elite models could be in development
Googlebook

Google has already confirmed that Googlebook will support more than one chipmaker, and a new leak may have revealed the first Snapdragon models in development.

New code references uncovered by GbookHub reportedly link two Googlebook designs, codenamed Annite and Pic, to Qualcomm’s Snapdragon X Plus X1P-42-100 processor. Both are also said to be tied to a board platform called Mica.

Read more