Pacman attack on M1 chip

6 views
Skip to first unread message

Bill Frantz

unread,
Jun 16, 2022, 10:59:18 PM6/16/22
to Design
From SANS NewsBites Vol. 24 Num. 47

<https://pacmanattack.com/>

This attack bypasses Pointer Authentication on the Apple M1 chip. It’s kind of fun in that it avoids crashes during the attack by running the attack in speculative execution and testing for success by looking at the TLB. They say they can use any side-channel, but they picked the TLB.

Cheers - Bill


Reply all
Reply to author
Forward
0 new messages