← Back to context

Comment by jsjohnst

2 years ago

Seems likely a compromise at the GPU or ARM side as equally possible routes.

What do you mean? Both the GPU and CPU design are proprietary to Apple. They used to use regular ARM designed cores but the last one of those before switching to their own core design was something like the A5 days (from memory). It uses the ARM instruction set but isn’t actually designed by ARM at all.

Similar for the GPU too. They may have started with HDL licensed from others (like I think their GPU might actually have been directly based on the PowerVR ones they used to use, but I believe the ARM one is basically from-scratch) but this vulnerability seems unlikely to have existed since then…

  • CoreSight is not Apple proprietary, it’s part of ARM’s offering. This vulnerability appears to be part of CoreSight.

    > but I believe the ARM one is basically from-scratch

    You are wrongly believing then. There’s still a bunch of ARM IP in their CPU.