• Sources: primary, HN submission
  • Summary: The paper names the attack SLAC and reverse-engineers the Apple M1 system-level cache set-indexing functions to build two channels. CPrime+CProbe primes and probes the shared cache from an unprivileged CPU process, and GPrime+CProbe leverages the GPU for faster priming, which the abstract credits with a 6.4x increase in covert-channel throughput. The authors report recovering LLM input keywords at up to 94.8 percent accuracy against TinyLlama and GPT-2 Medium, and the abstract does not attribute that figure to either channel. The paper is accepted to ACM CCS 2026, and it names no CVE, no vendor advisory, and no mitigation.
  • Why it matters: Local inference on Apple Silicon currently assumes the CPU and GPU boundary holds, and CPrime+CProbe crosses it from an unprivileged CPU process through shared cache.
  • Follow-up: Watch for an Apple advisory or a mitigation response.

send feedback on this story