
Novel Side-Channel Attack 'Tide' Targets Apple Silicon (M1–M5) for Website and Video Fingerprinting
The talk presents a novel side-channel attack on Apple systems, specifically targeting interrupt-based leakage on Apple Silicon (M1–M5) running macOS with the XNU kernel. The research introduces Tide, a timeless interrupt detection method exploiting the deterministic overwrite of the ARM platform register X18 during interrupt handling, enabled by Apple’s double-map mitigation and XNU’s exception process. Experiments demonstrate website fingerprinting with 93.8% top-1 accuracy (Alexa Top 100) and video fingerprinting with 78.1% top-1 accuracy (YouTube Top 20), validated across MacBook, Mac Mini, and iPhone 16 Pro. Apple acknowledged the findings but classified X18 register events as out of scope, with no immediate mitigation plans. Mitigation attempts via artificial noise reduced attack accuracy to ~60% with 10% overhead. The work highlights timeless side channels as a persistent risk even in closed ecosystems.