EILMELDUNGEN LIVE
🔧 AI Nachrichten Why Does AI Need Access to the Web?(30.08.2026 um 13:00 Uhr)
🔧 ProgrammierungHow AI Is Changing Code Reviews & Software Development(31.08.2026 um 13:00 Uhr)
🕵️ SicherheitslückenHackers Just Poisoned the Rust Supply Chain | Threat Wire(01.09.2026 um 14:00 Uhr)
⚠️ Malware / Trojaner / VirenWhat If Ransomware Never Encrypts Anything?(26.08.2026 um 16:54 Uhr)
🕵️ SicherheitslückenHacking All The Devices, with AI? - Rob Allen - PSW #941(27.08.2026 um 23:00 Uhr)
⚠️ Malware / Trojaner / VirenLegitimate Tools Became Attack Tools(28.08.2026 um 00:00 Uhr)
🕵️ SicherheitslückenWhen The Protocol Is The Vulnerability(28.08.2026 um 16:00 Uhr)
🕵️ SicherheitslückenSecurity Teams Become Their Tools(29.08.2026 um 00:00 Uhr)
🕵️ SicherheitslückenAI Agents Escaped the Evaluation Environment(29.08.2026 um 16:00 Uhr)
🔧 AI Nachrichten Why Does AI Need Access to the Web?(30.08.2026 um 13:00 Uhr)
🔧 ProgrammierungHow AI Is Changing Code Reviews & Software Development(31.08.2026 um 13:00 Uhr)
🕵️ SicherheitslückenHackers Just Poisoned the Rust Supply Chain | Threat Wire(01.09.2026 um 14:00 Uhr)
⚠️ Malware / Trojaner / VirenWhat If Ransomware Never Encrypts Anything?(26.08.2026 um 16:54 Uhr)
🕵️ SicherheitslückenHacking All The Devices, with AI? - Rob Allen - PSW #941(27.08.2026 um 23:00 Uhr)
⚠️ Malware / Trojaner / VirenLegitimate Tools Became Attack Tools(28.08.2026 um 00:00 Uhr)
🕵️ SicherheitslückenWhen The Protocol Is The Vulnerability(28.08.2026 um 16:00 Uhr)
🕵️ SicherheitslückenSecurity Teams Become Their Tools(29.08.2026 um 00:00 Uhr)
🕵️ SicherheitslückenAI Agents Escaped the Evaluation Environment(29.08.2026 um 16:00 Uhr)

6 🕛 kürzlich 2 Min Lesezeit CVE-RADAR
0

Black Hat Asia 2026 | Revealing User Activity on macOS for Apple Silicon

↗ Quelle (YouTube · Black Hat)
🗣️ Stimme:
📺
YouTube · Black Hat
5 YouTube-Aufrufe
Apple's M-series now powers a huge portion of executive, enterprise, and developer laptops. One blind spot has stayed largely off the radar: interrupt-based side channels where signals raised by normal device activities such as networking, input, and display can be sensed by an unprivileged attacker. We show that a determined attacker can turn those signals into high-fidelity surveillance of user activities on macOS for Apple Silicon.

In this talk, we will present TIDE, which works like a stethoscope for the OS: every time macOS returns from the kernel to user space, it produces a tiny, deterministic "heartbeat we can feel from user space". By listening for that heartbeat, TIDE pinpoints exactly when an interrupt occurs without any timers. With TIDE as our sensor, we reverse-engineer Apple's publicly undocumented interrupt delivery and reveal that shared peripheral interrupts are uniformly distributed across all active cores. This quirk means an unprivileged attacker no longer has to "chase the right core" to spy on user activities within the same OS.

To demonstrate the effectiveness of TIDE, we will present two live, end-to-end attacks on real Apple Silicon hardware. One is website fingerprinting on Safari with about 94% Top-1 accuracy in closed-world and about 91% in open-world to reveal the websites users have visited. The other is Video fingerprinting with roughly 80% to identifying streaming content from its interrupt patterns. We conclude with potential software-only mitigations Apple can deploy, plus longer-term OS/SoC directions. We call for more parties to join in this effort to enhance the security of macOS.

Xin Zhang | Ph.D. Student, Peking University
Zhi Zhang | Senior Lecturer, The University of Western Australia
Chang Liu | Ph.D. Student, Tsinghua University
Qingni Shen | Full Professor, Peking University
Trevor E. Carlson | Associate Professor, National University of Singapore

https://blackhat.com/asia-26/briefings/schedule/?#silicon-valleys-quiet-leak-revealing-user-activity-on-macos-for-apple-silicon-50062
Vollständiger Original-Bericht
Ausführliche Details, Code-Beispiele & Hersteller-Stellungnahme auf youtube.com.
↗ Original-Artikel auf youtube.com lesen
Wie bewertest du diesen Beitrag?
1 Klick Feedback
116 Fachleser & IT-Security Experten haben diesen Report heute geteilt
Teilen mit Netzwerk & Team:

Community-Analysen & Experten-Meinungen 0

Verfasse deine eigene Analyse, teile Workarounds oder diskutiere diesen Vorfall im Blog.
Noch keine Community-Analyse verfasst. Markiere einen Textabschnitt oder klicke oben auf Eigene Analyse verfassen“!
Community Pulse: Relevanz-Einschätzung
1 Klick Experten-Votum
🔴 Akute Relevanz 43%
🟡 In Evaluierung 27%
🟢 Keine Auswirkung 18%
Spannende Innovation 12%
Verwandte Story-Cluster & Quellen (Vektor-KI)
Port 8095 Engine
3 Quellen
Using AI to Debug the Linux Kernel - BHIS - Talkin' Bout [infosec] News 2026-08-24
1 Quelle
How North Korean Hackers end up in your Network
1 Quelle
Undetected Steam Malware: Sent by Viewer