Apple M1: Security vulnerability PACman cannot be fixed

VG word pixels

Vulnerability in the CPU

Apple’s M1 chip has a security vulnerability that cannot be fixed with an update. According to MIT researchers, PACman also allows attacks against the kernel of the operating system.

news

VG word pixels

Apple M1 logo
Ever since the M1, Apple has been building its processors in-house.
©Apple

With PACman, a new vulnerability was found in Apple’s M1 processor series. The vulnerability was discovered by Researchers from the Massachusetts Institute of Technology (MIT). Since the problem exists at the hardware level, it cannot simply be fixed with an update. Furthermore, other ARM-based chips, for example from Qualcomm or Samsung, could also be affected by the vulnerability.

The vulnerability is found in the processor’s Pointer Authentication Code (PAC). This is a CPU security mechanism that places a cryptographic signature in the first bits of a pointer. This allows apps to be checked for malicious changes and unauthorized reading of content can be prevented.

However, the possible values ​​of the PAC can be checked quickly enough to find out the correct authentication code. Theoretically, such deep attacks are possible, for example on the kernel of the operating system – but only if further security mechanisms of the M1 could be circumvented and the PAC is only the last line of defense.

Apple itself classifies the vulnerability as “Techcrunch” as a low risk. Thank you “the researchers for their work, because the proof of concept advances our understanding of such techniques.” The researchers at MIT were able to determine whether the vulnerability is also present in Apple’s newly announced M2 processor can’t find out at this point.

M2 processor

More power & efficiency

M2: Apple shows the next generation of processors

During the WWDC 2022, Apple showed the new M2 processors. The chips bring more performance with less power consumption and will be available from July.

13.6.2022 from
Alan Friedrichs

Continue to home page

more on the subject

Password manager test 2021

Online Safety

Apple, Google and Microsoft encourage login without a password

Large companies such as Apple, Google and Microsoft want to encourage logins without a password in the future. As an alternative, the extended FIDO standard…

CPU's: 6 desktop processors in the comparison test

May patch day at the CPU manufacturers

AMD and Intel patch processor vulnerabilities

The two processor manufacturers Intel and AMD have released security patches that fix several vulnerabilities in CPUs and peripherals.

Router on a desk.  In the background a man is using his smartphone and laptop

IT security label

BSI is now labeling secure routers

Whether the new router meets current security requirements will soon become clearer. The BSI will now issue a corresponding indicator.

M2 processor

More power & efficiency

M2: Apple shows the next generation of processors

During the WWDC 2022, Apple showed the new M2 processors. The chips bring more performance with less power consumption and will be available from July.

remove virus

Beware of Trojans

CCleaner free: Fake download turns out to be malware

A trojan is currently in circulation, which is distributed via a fake CCleaner license. The malware steals passwords and credit cards…

Reference-www.pc-magazin.de