4 ms·
Is the statement from Apple just PR or is this not a usable exploit? "Based on our analysis, we do not believe this issue poses an immediate risk to our users.
by alphabetting 2y ago
Is the statement from Apple just PR or is this not a usable exploit?
"Based on our analysis, we do not believe this issue poses an immediate risk to our users."
https://www.bleepingcomputer.com/news/security/new-apple-cpu-side-channel-attack-steals-data-from-browsers/ https://www.bleepingcomputer.com/news/security/new-apple-cpu...
- keyle 2y agoApple PR, which is unlike them; to wave it off.
- hashstring 2y agoThey carefully added “immediate”.
- rasz 2y ago>statement from Apple just PR remember the iphone 6 battery and butterfly keyboard gate we both "small number of users" according to Apple.
- bjackman 2y agoCPU vendors always say this when an exploit is published before they mitigate. Sometimes they mean "no we don't think it's exploitable", sometimes the charitable reading is "we don't think anyone is exploiting this and we think developing an exploit will take quite some time". Unfortunately they never reveal exactly that they mean. This is very annoying, because when it's the former case, they're often right! Security researchers publish bullshit sometimes. But the vendors basically leave you to figure it out for yourself.
- philodeon 2y agoGiven that the researchers published working exploits that you can modify for your own use, it’s PR.
- fulafel 2y agoAnd from the paper seems like they played it interestingly in the researchers direction as well: "1.2. Responsible Disclosure We disclosed our results to Apple on May 24, 2024. Apple’s Product Security Team have acknowledged our report and proof-of-concept code, requesting an extended embargo beyond the 90-day window. At the time of writing, Apple did not share any schedule regarding mitigation plans concerning the results presented in this paper. "