• Home
  • Startup
  • Money & Finance
  • Starting a Business
    • Branding
    • Business Ideas
    • Business Models
    • Business Plans
    • Fundraising
  • Growing a Business
  • More
    • Innovation
    • Leadership
Trending

Why Conversational Commerce is the Future of Shopping

May 29, 2025

10 Leadership Myths You Need to Stop Believing

May 29, 2025

Tesla’s Layoffs Won’t Solve Its Growing Pains

May 29, 2025
Facebook Twitter Instagram
  • Newsletter
  • Submit Articles
  • Privacy
  • Advertise
  • Contact
Facebook Twitter Instagram
InDirectica
  • Home
  • Startup
  • Money & Finance
  • Starting a Business
    • Branding
    • Business Ideas
    • Business Models
    • Business Plans
    • Fundraising
  • Growing a Business
  • More
    • Innovation
    • Leadership
Subscribe for Alerts
InDirectica
Home » iLeakage Hackers Can Read Gmail On All 2020 Or Later iPhones And Macs
Innovation

iLeakage Hackers Can Read Gmail On All 2020 Or Later iPhones And Macs

adminBy adminOctober 28, 20230 ViewsNo Comments3 Mins Read
Facebook Twitter Pinterest LinkedIn Tumblr Email

Security researchers funded by the U.S. Air Force Officer of Scientific Research and the Defense Advanced Research Projects Agency have revealed how hackers can extract data, including your Gmail inbox, from Apple devices running iOS, iPadOS and macOS. Dubbed iLeakage, this side-channel attack can be deployed against Apple devices from 2020 onwards with the A and M series CPUs and targets the Safari web browser as well as any browser app running on an iPhone or iPad.

What Is The iLeakage Exploit?

The researchers from the Georgia Institute of Technology, the University of Michigan and the Ruhr University in Germany, included those responsible for uncovering the so-called Spectre speculative execution attacks in 2018. iLeakage uses the same kind of speculative execution to conduct attacks against Safari on macOS devices. However, it works against any browser on iPhones and iPads, thanks to them being required to use Apple’s WebKit engine under the hood.

In their paper, iLeakage: Browser-based Timerless Speculative Execution Attacks on Apple Devices, the researchers reveal the full extent to which this exploit could be used. A hacker could recover sensitive information by inducing Safari or another WebKit-based browser to render an arbitrary page. “In particular, we demonstrate how Safari allows a malicious webpage to recover secrets from popular high-value targets,” the researchers reveal, including “Gmail inbox content.” But the problems don’t end there; the researchers also demonstrate exploits that can lead to “the recovery of passwords” when auto-filled by password managers.

How An iLeakage Attack Could Read Your iPhone Gmail Inbox

The paper states that when it comes to Gmail, one of the world’s most popular email providers with billions of users, an exploit target is likely to be signed into their personal Google account. “By having the event listener inside the attacker’s page access execute window.open(gmail.com),” the researchers explain, “we can consolidate the target’s inbox view into the attacker’s address space. We then leak the contents of the target’s inbox.” I have approached Apple and Google for a statement and will update this article if one is provided.

Mitigating The iLeakage Attack Scenario

According to the researchers, Apple was made aware of the iLeakage exploit discovery on September 12, 2022. So far, the only mitigation from Apple in more than a year would appear to be reserved for Safari on Macs only running macOS Ventura 13.0 or later, which is considered unstable in use and isn’t enabled by default. You can view the precise details in the iLeakage FAQ. There is no mitigation for iPhone or iPad users at this point in time, although Apple is understood to be working on a fix.

Are Attackers Already Exploiting iLeakage?

The good news is, as far as is known, that iLeakage exploits have not been used in the wild. Not least because, as the researchers note, it is a “significantly difficult attack to orchestrate end-to-end, and requires advanced knowledge of browser-based side-channel attacks and Safari’s implementation.” The bad news is that iLeakage leaves no traces of an attack within system log files, although the attacking web page might be found in the browser cache, as it runs within Safari. The researchers have confirmed that it’s “highly unlikely” for an attack to be detected.

Read the full article here

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email

Related Articles

Going Eco Benefits Planet And This Hotel’s Bottom Line

Innovation May 29, 2025

What IBM’s Deal For HashiCorp Means For The Cloud Infra Battle

Innovation April 25, 2024

Is Telepathy Possible? Perhaps, Due To New Technology

Innovation April 24, 2024

Luminar Launches Production For Volvo, Shows Next-Gen Halo Lidar

Innovation April 23, 2024

Turning Customers Into Investors – Tiny Health’s Experience

Innovation April 22, 2024

Netflix’s Best New Original Series Is Stressing Me Out

Innovation April 21, 2024
Add A Comment

Leave A Reply Cancel Reply

Editors Picks

Why Conversational Commerce is the Future of Shopping

May 29, 2025

10 Leadership Myths You Need to Stop Believing

May 29, 2025

Tesla’s Layoffs Won’t Solve Its Growing Pains

May 29, 2025

Going Eco Benefits Planet And This Hotel’s Bottom Line

May 29, 2025

What IBM’s Deal For HashiCorp Means For The Cloud Infra Battle

April 25, 2024

Latest Posts

The Future of Football Comes Down to These Two Words, Says This CEO

April 25, 2024

This Side Hustle Is Helping Land-Owners Earn Up to $60,000 a Year

April 25, 2024

A Wave of AI Tools Is Set to Transform Work Meetings

April 25, 2024

Is Telepathy Possible? Perhaps, Due To New Technology

April 24, 2024

How to Control the Way People Think About You

April 24, 2024
Advertisement
Demo

InDirectica is your one-stop website for the latest news and updates about how to start a business, follow us now to get the news that matters to you.

Facebook Twitter Instagram Pinterest YouTube
Sections
  • Growing a Business
  • Innovation
  • Leadership
  • Money & Finance
  • Starting a Business
Trending Topics
  • Branding
  • Business Ideas
  • Business Models
  • Business Plans
  • Fundraising

Subscribe to Updates

Get the latest business and startup news and updates directly to your inbox.

© 2025 InDirectica. All Rights Reserved.
  • Privacy Policy
  • Terms of use
  • Press Release
  • Advertise
  • Contact

Type above and press Enter to search. Press Esc to cancel.