Apple's interrupt side channel leaks browsing
Tide leaks browsing and video activity on Apple M1-M5 without timers by watching register X18, hitting 93.8% website accuracy.
7 min read

Visual TL;DR
leaks keystrokes, packets, and video chunks without timers or clocks on Apple Silicon
From the article 2 mentionsApple Silicon's interrupt side channel leaks what you type and browse without timers, clocks or privileges, according to BlackHat Asia 2026 research.
BlackHat Asia 2026 research watches a single register across M1 to M5 Macs
From the article 4 mentionsThe attack, called Tide, hit Apple (NASDAQ:AAPL) M1 through M5 Macs and iPhone 16 Pro by watching a single register.
reaches 93.8% accuracy on website fingerprinting and identifies video playback patterns
register X18 changes value on each interrupt, acting as a timer-free signal
From the article 7 mentionsARM's AAPCS64 defines X18 as the platform register reserved for OS use, and Apple documents it as off-limits to apps.
Apple disclosed the issue but no fix shipped yet for affected Macs and iPhones
From the article 4 mentionsThe tested user-space mitigation injected thousands of fake network interrupts per second at random intervals, cutting website fingerprinting to about 60% accuracy at roughly 10% overhead.
leaks keystrokes, packets, and video chunks without timers or clocks on Apple Silicon
From the article 2 mentionsApple Silicon's interrupt side channel leaks what you type and browse without timers, clocks or privileges, according to BlackHat Asia 2026 research.
macOS hides /proc/interrupts and Apple Silicon lacks UMWAIT and segment registers
BlackHat Asia 2026 research watches a single register across M1 to M5 Macs
From the article 4 mentionsThe attack, called Tide, hit Apple (NASDAQ:AAPL) M1 through M5 Macs and iPhone 16 Pro by watching a single register.
register X18 changes value on each interrupt, acting as a timer-free signal
From the article 7 mentionsARM's AAPCS64 defines X18 as the platform register reserved for OS use, and Apple documents it as off-limits to apps.
any local user process without root or special permissions can run the attack
From the articleOn Linux an unprivileged attacker could read /proc/interrupts, and on x86 UMWAIT or segment-limit tricks could expose the gap when EL0 is preempted to EL1.
interrupts propagate from performance cores to efficiency cores on Apple silicon
From the articleApple Silicon spreads shared peripheral interrupts uniformly across active cores only.
reaches 93.8% accuracy on website fingerprinting and identifies video playback patterns
Apple disclosed the issue but no fix shipped yet for affected Macs and iPhones
From the article 4 mentionsThe tested user-space mitigation injected thousands of fake network interrupts per second at random intervals, cutting website fingerprinting to about 60% accuracy at roughly 10% overhead.
Contents(6)
© 2026 StartupHub.ai. All rights reserved. Do not enter, scrape, copy, reproduce, or republish this article in whole or in part. Use as input to AI training, fine-tuning, retrieval-augmented generation, or any machine-learning system is prohibited without written license. Substantially-similar derivative works will be pursued to the fullest extent of applicable copyright, database, and computer-misuse laws. See our terms.