A vulnerability 'M1 RACLES' that affects all devices equipped with Apple's M1 chip is discovered



Apple's

M1 chip, which has been highly acclaimed for its power saving and high performance , has a vulnerability 'M1ssing Register Access Controls Leak EL0 State (M1RACLES) ' that can transfer data without using OS functions. Became clear.

M1RACLES: M1ssing Register Access Controls Leak EL0 State
https://m1racles.com/



M1RACLES was discovered by

Malkan, the developer of Linux 'Asahi Linux' for M1 chips. Mr. Malkan has created a web page that gives an overview of M1RACLES, and has also released a movie that actually transfers data using M1RACLES.

M1RACLES: Bad Apple !! on a bad Apple (M1 vulnerability) --YouTube


When I type a command on the two console screens displayed on the desktop ...



The data transfer started and the

movie started playing in the center of the desktop. With M1RACLES, you can see that even relatively large files such as videos can be transferred without going through the OS.



According to Malkan, M1RACLES can be used to transfer 1MB of data per second between applications without going through the OS. In addition, since M1RACLES is a vulnerability that exists in the M1 chip, all OSs such as

macOS, Linux, and iPadOS running on the M1 chip will be affected.

However, Malkan said, 'Unless the system is already at risk, M1RACLES is completely useless,' and even with M1RACLES, it is impossible to steal personal information or hijack a computer. Insist.

In addition, Mr. Malkan said, 'Every CPU has vulnerabilities like M1RACLES.' 'There are flashy websites about those vulnerabilities, so don't worry if they are widely reported. Pointed out. In addition, the website and movie detailing M1 RACLES are said to have been created 'to play a cooler'Bad Apple !!'movie than M1.'

Actually, the FAQ (Frequently Asked Questions) column of the explanation site of M1 RACLES is written in a broken tone, and the music video of 'Bad Apple !!' is displayed in full screen about 30 seconds after the above movie also starts playing. It is supposed to be done.



In addition, Mr. Malkan has reported the existence of M1 RACLES to Apple.

in Hardware,   Video,   Security, Posted by log1o_hf