Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Endpoint Security

Researchers Show First Side-Channel Attack Against Apple M1 Chips

New Browser Side-Channel Attack Doesn’t Require JavaScript

New Browser Side-Channel Attack Doesn’t Require JavaScript

A team of researchers from universities in the United States, Australia and Israel has demonstrated that attackers could launch browser-based side-channel attacks that do not require JavaScript, and they’ve tested the method on a wide range of platforms, including devices that use Apple’s recently introduced M1 chip.

The researchers — representing the Ben-Gurion University of the Negev, the University of Michigan and the University of Adelaide — have published a paper on what they have described as the first browser side-channel attack that uses only CSS and HTML, and works even if JavaScript is completely disabled.

The analysis focused on Prime+Probe, a cache side-channel attack method that can detect which cache sets are accessed by the target and uses that to infer potentially valuable information.

Conducting these types of attacks in the browser typically involves the execution of JavaScript code and timing measurements. Web browsers vendors and third parties have been working on developing protections against such attacks, including by limiting or completely preventing JavaScript execution and by trying to prevent attackers from precisely measuring time.

The researchers have developed a sequence of attacks where they have progressively decreased dependency on JavaScript features, which resulted in a method that relies entirely on HTML and CSS. They claim to have shown that all existing countermeasures can be bypassed.

The attack method has been successfully tested — with various levels of success depending on the targeted architecture and existing mitigations — against hardened browser environments (e.g. Tor, Chrome Zero, DeterFox) on devices with Intel, AMD, Samsung and Apple chips.

Side-channel attack test results

Impacted vendors have been notified. Apple told the researchers that the public disclosure of their findings does not raise any concerns.

Advertisement. Scroll to continue reading.

“We show that advanced variants of the cache contention attack allow Prime+Probe attacks to be mounted through the browser in extremely constrained situations,” the researchers said in their paper. “Cache attacks cannot be prevented by reduced timer resolution, by the abolition of timers, threads, or arrays, or even by completely disabling scripting support. This implies that any secret-bearing process which shares cache resources with a browser connecting to untrusted websites is potentially at risk of exposure.”

Related: New Technique Improves Effectiveness of Timing Channel Attacks

Related: New Side-Channel Attack Targets Intel CPU Ring Interconnect

Related: New Side-Channel Attack Targets OS Page Cache

Written By

Eduard Kovacs (@EduardKovacs) is a managing editor at SecurityWeek. He worked as a high school IT teacher for two years before starting a career in journalism as Softpedia’s security news reporter. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering.

Click to comment

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join the session as we discuss the challenges and best practices for cybersecurity leaders managing cloud identities.

Register

SecurityWeek’s Ransomware Resilience and Recovery Summit helps businesses to plan, prepare, and recover from a ransomware incident.

Register

Expert Insights

Related Content

Vulnerabilities

Less than a week after announcing that it would suspended service indefinitely due to a conflict with an (at the time) unnamed security researcher...

Data Breaches

OpenAI has confirmed a ChatGPT data breach on the same day a security firm reported seeing the use of a component affected by an...

IoT Security

A group of seven security researchers have discovered numerous vulnerabilities in vehicles from 16 car makers, including bugs that allowed them to control car...

Vulnerabilities

A researcher at IOActive discovered that home security systems from SimpliSafe are plagued by a vulnerability that allows tech savvy burglars to remotely disable...

Risk Management

The supply chain threat is directly linked to attack surface management, but the supply chain must be known and understood before it can be...

Cybercrime

Patch Tuesday: Microsoft calls attention to a series of zero-day remote code execution attacks hitting its Office productivity suite.

Vulnerabilities

Patch Tuesday: Microsoft warns vulnerability (CVE-2023-23397) could lead to exploitation before an email is viewed in the Preview Pane.

Vulnerabilities

The latest Chrome update brings patches for eight vulnerabilities, including seven reported by external researchers.