'
When pointer authentication was introduced, a whole category of bugs suddenly became a lot harder to use for attacks. With 'PACMAN' making these bugs more serious, the overall attack surface could be a lot larger," he added.'Pointer authentication' is primarily used to protect the core operating system kernel, the most privileged part of the system. An attacker who gains control of the kernel can do whatever they'd like on a device. The team showed that the 'PACMAN' attack even works against the kernel, which has "massive implications for future security work on all ARM systems with pointer authentication enabled". "Future CPU designers should take care to consider this attack when building the secure systems of tomorrow," Ravichandran said in the paper that was published late on Friday. "Developers should take care to not solely rely on pointer authentication to protect their software," he added.Apple has implemented 'pointer authentication' on all of its custom ARM-based silicon so far, including the M1, M1 Pro and M1 Max."If not mitigated, our attack will affect the majority of mobile devices, and likely even desktop devices in the coming years," MIT said in the research paper.An Apple spokesperson told TechCrunch that the company wants to "thank the researchers for their collaboration as this proof of concept advances our understanding of these techniques". "Based on our analysis as well as the details shared with us by the researchers, we have concluded this issue does not pose an immediate risk to our users and is insufficient to bypass operating system security protections on its own," the company's spokesperson added.
--IANS na/svn/
(Disclaimer: This post has been auto published from IANS news agency without any modification to the text and has not been reviewed by editor)