Skip to main content

Apple’s M1 chip has a flaw, but you shouldn’t worry

Apple’s M1 chip has revitalized its Mac lineup, but a developer has discovered a flaw they say is “baked into Apple Silicon chips, and cannot be fixed without a new silicon revision.” There is probably no need to worry, though, as the same researcher says the impact of this flaw is negligible.

The exploit allows two apps to pass data between them without the use of files, memory, or any of the other regular ways data is exchanged in an operating system, says Hector Martin, the developer who found the flaw. It can even pass things between users and across privilege levels.

Martin warns that this defect is part of all Apple Silicon chips and cannot be remedied without Apple addressing the issue in future silicon designs. In other words, Apple cannot simply release a patch or get users to update their Macs to fix things. And since iPhone chips are also based on Apple Silicon, they too are affected (although Apple’s App Store should snuff out apps that use this exploit automatically, says Martin).

No need to panic

Still, Martin is careful to explain that the risks to ordinary users are minimal. In a Q&A section on his website dedicated to the exploit, Martin outlines exactly what it can and cannot do:

Can malware use this vulnerability to take over my computer?
No.

Can malware use this vulnerability to steal my private information?
No.

Can malware use this vulnerability to rickroll me?
Yes. I mean, it could also rickroll you without using it.

Can this be exploited from JavaScript on a website?
No.

So, what can it be used to do? Advertising companies could potentially use this to bypass Apple’s cross-app tracking protections, but that is about it, says Martin. He is blunt about its malicious uses: “Really, nobody’s going to actually find a nefarious use for this flaw in practical circumstances.”

In fact, Martin says the whole purpose of his website is to “[Poke] fun at how ridiculous infosec clickbait vulnerability reporting has become lately. Just because it has a flashy website or it makes the news doesn’t mean you need to care.”

So if you have an M1 Mac, there is no need to panic. Apple is aware of the bug and is likely working on a fix, but it is unlikely this exploit will cause any sort of widespread disruption. As Martin explains, bad actors have plenty of other, more efficient ways to cause trouble. Getting an antivirus app on your Mac and exercising good common sense will go a long way to keeping you protected.

Editors' Recommendations

Alex Blake
In ancient times, people like Alex would have been shunned for their nerdy ways and strange opinions on cheese. Today, he…
Here’s why WWDC could be a ‘critical event’ for Apple
Apple CEO Tim Cook looks at a display of brand new redesigned MacBook Air laptop during the WWDC22

Apple is planning a packed line-up for its Worldwide Developers Conference (WWDC) on June 5, which could become “one of the most critical events in the company’s history.” Aside from the company’s upcoming Reality Pro headset, there will be major updates to Apple’s software systems, including the biggest watchOS revamp since the Apple Watch launched in 2015.

That’s according to a new report from Bloomberg journalist Mark Gurman, who has a history of accurate predictions and leaks surrounding Apple products. It suggests that WWDC will be a chance for Apple to set out its future ambitions for a “post-iPhone era.”

Read more
Apple could soon put an M3 chip in its worst laptop
Fortnite running on a Macbook M1.

Apple’s MacBook lineup is full of great laptops, but the 13-inch MacBook Pro really doesn’t feel like it belongs. Yet a new report claims Apple will update that device with an M3 chip later this year instead of simply killing it off.

The news comes from 9to5Mac, and the website says its sources have confirmed the 13-inch MacBook Pro is going to get a refresh with a new M3 chip, potentially at Apple’s Worldwide Developers Conference (WWDC) in June.

Read more
This major Apple bug could let hackers steal your photos and wipe your device
A physical lock placed on a keyboard to represent a locked keyboard.

Apple’s macOS and iOS are often considered to be more secure than their rivals, but that doesn’t make them invulnerable. One security team recently proved that by showing how hackers could exploit Apple’s systems to access your messages, location data, and photos -- and even wipe your device entirely.

The discoveries were published on the blog of security research firm Trellix, and will be of major concern to iOS and macOS users alike, since the vulnerabilities can be exploited on both operating systems. Trellix explains that Apple patched the exploits in macOS 13.2 and iOS 16.3, which were released in January 2023, so you should update your devices as soon as you can.

Read more