Apple to Patch Web Browser Vulnerabilities Affecting Recent Macs, iPads and iPhones - MacRumorsOpen MenuShow RoundupsShow Forums menuVisit ForumsOpen Sidebar
Skip to Content

Apple to Patch Web Browser Vulnerabilities Affecting Recent Macs, iPads and iPhones

There are two new speculative execution attacks that impact recent Apple chips, according to data shared today by Georgia Tech students that discovered the vulnerabilities.

slap flop vulnerabilities
Named SLAP and FLOP, the two security flaws could allow an attacker to use a malicious webpage to spy on the contents of other webpages, giving attackers remote access to browsing history, credit card data, emails, location information, and more. Physical access to a device is not required, and the attack can be executed through a malicious site that bypasses Apple's browser protections.

Several Apple A-series and M-series chips are affected, including the M2 and later and the A15 and later, which are in the following devices:

  • 2022 and later Mac notebooks
  • 2023 and later Mac desktops
  • 2021 and later iPad models
  • 2021 and later iPhones

SLAP and FLOP were disclosed to Apple in May 2024 and September 2024, respectively, and while the attacks have not yet been patched, the researchers who reported the issue were told that Apple plans to address the vulnerabilities in an upcoming security update.

Apple told Bleeping Computer that it has not yet patched the flaws. "We want to thank the researchers for their collaboration as this proof of concept advances our understanding of these types of threats," Apple said. "Based on our analysis, we do not believe this issue poses an immediate risk to our users."

SLAP affects Safari, while FLOP affects Safari and Chrome. Other browsers like Firefox could be affected too, but have not been tested. There is no evidence that SLAP and FLOP have been executed in the wild.

Details on how SLAP and FLOP work can be found on the website dedicated to explaining the vulnerabilities.

Popular Stories

General macOS Mail Feature

Apple Patches Hide My Email Flaw More Than a Year After It Was Reported

Tuesday July 21, 2026 10:10 am PDT by
Apple addressed a vulnerability in Hide My Email that exposed a user's real email address, reports 404 Media. Apple told the site the issue was fully fixed in a patch released on July 3. The Hide My Email vulnerability was brought to Apple's attention in June 2025, but the company did not fix it until 404 Media publicized the bug in early July. EasyOptOuts co-founder Tyler Murphy, who...
apple lock security bug vulnerability fix privacy

Update Now: iOS 26.6 and macOS Tahoe 26.6 Patch Hundreds of Security Flaws

Monday July 27, 2026 11:55 am PDT by
Apple today released iOS 26.6, iPadOS 26.6, and macOS Tahoe 26.6, all of which have a long list of security fixes. iOS 26.6 and iPadOS 26.6 address almost 90 security vulnerabilities affecting everything from the App Store to the Neural Engine. Multiple kernel and WebKit vulnerabilities were fixed, along with problems affecting Wi-Fi, Siri, and the iPhone's image processing. Details on...
Four iPhone 18 Pro Colors Mock Feature

iPhone 18 Pro and iPhone Ultra: Pre-Orders and Release Date

Thursday July 30, 2026 6:12 am PDT by
Apple has yet to reveal when the iPhone 18 Pro and iPhone Ultra will be announced and released, but the dates usually follow a familiar pattern. Labor Day is September 7 this year. The last time the holiday fell on that day was in 2020, but the iPhone event that year was delayed until October due to the COVID-19 pandemic. So, the last time Labor Day was on September 7 in a normal year was in ...

Top Rated Comments

awer25 Avatar
20 months ago
Help us Genmoji, you're our only hope!
Score: 29 Votes (Like | Disagree)
canadianreader Avatar
20 months ago

Apple told Bleeping Computer ('https://www.bleepingcomputer.com/news/security/new-apple-cpu-side-channel-attack-steals-data-from-browsers/') that it has not yet patched the flaws. "We want to thank the researchers for their collaboration as this proof of concept advances our understanding of these types of threats," Apple said. "Based on our analysis, we do not believe this issue poses an immediate risk to our users."
They're too busy fixing Apple Intelligence.
Score: 24 Votes (Like | Disagree)
centauratlas Avatar
20 months ago
"we do not believe this issue poses an immediate risk to our users." That may have been true but now that it was published in the two papers that Bleeping links to I would suspect that would change. Apple should have patched these. Reminds me of Meltdown and Spectre.
Score: 22 Votes (Like | Disagree)
Apple Knowledge Navigator Avatar
20 months ago
Have they patched the other FLOP?
Think it’s called Apple Intelligence.
Score: 20 Votes (Like | Disagree)
DeftwillP Avatar
20 months ago
It's ok guy, siri's got this.

"hey siri, load the patch from apple for the newest exploit"
"I couldn't find that person in your contacts"
Score: 20 Votes (Like | Disagree)
Razorpit Avatar
20 months ago

They're too busy fixing Apple Intelligence.
Maybe we can have Apple Intelligence write a patch! What could go wrong? 😁
Score: 12 Votes (Like | Disagree)

πŸ”— Related Apple News & Rumors

Stay updated with the latest Apple ecosystem news and verified rumors