LeftoverLocals GPU Flaw Exposes AI Data in Devices Equipped with Apple, AMD, and Qualcomm Hardware

LeftoverLocals does not impact GPUs from Arm, Nvidia, and Intel, according to the security researchers who uncovered the flaw,.

Advertisement
Written by David Delima, Edited by Siddharth Suvarna | Updated: 18 January 2024 15:42 IST
Highlights
  • LeftoverLocals affects GPUs from four major manufacturers
  • The flaw is said to impact some iPhone, iPad, and MacBook models
  • Manufacturers have issued patches for LeftooverLocals for select devices

GPUs from AMD and Apple are affected by the LeftoverLocals flaw

Photo Credit: Unsplash/ Joseph Greve

A security flaw affecting GPUs from four hardware manufacturers that exposed artificial intelligence (AI) data was unearthed by security researchers. The issue impacts several devices equipped with GPUs from these firms, including some iPhone, iPad, and Mac computers. Hackers can exfiltrate personal information being used in AI operations on the local memory of affected devices — including large language models (LLMs) used by services like Google, Meta, ChatGPT maker OpenAI, and Microsoft using a few lines of code, according to researchers.

Researchers at Trail of Bits uncovered a security flaw affecting GPUs from AMD, Apple, Imagination, and Qualcomm that has been dubbed LeftoverLocals. This vulnerability is related to the affected device's GPU and allows hackers to access information via local memory created by another process. Arm, Intel, and Nvidia GPUs are reportedly unaffected by the same security flaw.

In a detailed disclosure published earlier this week, the researchers highlight how the security flaw affects LLMs and machine learning (ML) models that are run on impacted devices. They were able to build a proof of concept (PoC) of the attack that allowed them to access information from another user's LLM session that was being run in a different process.

Advertisement

A demonstration of an attacker listening in on an interactive LLM chat session
Photo Credit: Screenshot/ Trail of Bits

Advertisement

 

By running a few lines of code, a hacker can use the LeftoverLocals security flaw to reconstruct the LLM response in an interactive session "with high precision", according to the researchers. The flaw was discovered by Tyler Sorensen and is being tracked by CVE-2023-4969.

Advertisement

The researchers state that they reached out to Apple and received a response on January 13, while the company has patched some devices with the A17 Pro — that powers the iPhone 15 Pro and 15 Pro Max — and M3 chip series, but other devices have not been patched, such as the M2-powered MacBook Air.

Meanwhile, AMD has stated is still exploring ways to mitigate the security vulnerability and Qualcomm has issued a patch with its v2.07 firmware that fixes the flaw on some devices, while others could still remain impacted. Affected Imagination GPUs were patched last month as part of the recent DDK 23.3 release, according to the researchers.

Advertisement


Is the Samsung Galaxy Z Flip 5 the best foldable phone you can buy in India right now? We discuss the company's new clamshell-style foldable handset on the latest episode of Orbital, the Gadgets 360 podcast. Orbital is available on Spotify, Gaana, JioSaavn, Google Podcasts, Apple Podcasts, Amazon Music and wherever you get your podcasts.
Affiliate links may be automatically generated - see our ethics statement for details.
 
REVIEW
  • Design
  • Display
  • Software
  • Performance
  • Battery Life
  • Value for Money
  • Good
  • Stylish and functional design
  • Very good battery life, MagSafe charging
  • Crisp and bright display
  • Great performance, excellent keyboard
  • Speakers sound good
  • Bad
  • Expensive
 
KEY SPECS
Display size 13.60-inch
Touchscreen No
Processor Apple M2
RAM 8GB
OS macOS
Hard disk No
SSD 512GB
NEWS
REVIEW
  • Design
  • Display
  • Software
  • Performance
  • Battery Life
  • Camera
  • Value for Money
  • Good
  • Excellent display
  • USB Type-C
  • AAA gaming
  • Excellent all-round performance
  • Good primary and telephoto camera
  • Customisable Action Button
  • Bad
  • Gets hot quickly when stressed
  • Slow wired charging
  • Expensive
 
KEY SPECS
Display 6.70-inch
Processor Apple A17 Pro
Front Camera 12-megapixel
Rear Camera 48-megapixel + 12-megapixel + 12-megapixel
RAM 8GB
Storage 256GB, 512GB, 1TB
OS iOS 17
Resolution 1290x2796 pixels
NEWS

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Advertisement
Popular Mobile Brands
  1. MacBook Air (2025) With M4 Chip Available at This Discounted Price
  2. Pixel 10 Series Gets Price Cuts During Google's End of Year Sale: See Offers
  3. OnePlus 15R Storage Options Leaked: Here's How Much It Might Cost in India
  4. Mrs Deshpande OTT Release Date: Madhuri Dixit's Starrere to Premiere on This Date
  5. RAM Crisis 2026: 16GB Phones Out, 4GB Models Making a Comeback
  6. Logitech MX Master 4 Launches in India With These Features
  7. Apple Fitness+ Service Is Now Available in India: See Features
  8. Redmi Note 15 5G Chipset Revealed Ahead of January 6 India Launch
  9. Vivo S50, S50 Pro Mini With Snapdragon Chips Launched at These Prices
  10. Motorola Edge 70 First Impressions
  1. Lakshmi Manchu’s Daksha: The Deadly Conspiracy Available for Streaming on Amazon Prime Video
  2. Posthouse Now Available to Stream on Netflix: Know Everything About This Psychological Thriller Film
  3. Redmi Note 15 5G Chipset Confirmed Ahead of January 6 Launch in India: Expected Features, Specifications
  4. Lenovo Idea Tab Plus Launched in India With 12.1-Inch Display, 10,200mAh Battery: Price, Specifications
  5. The End of 16GB RAM Phones? AI Boom Forces Smartphone Makers to Bring Back 4GB Models
  6. Xiaomi 17 Ultra Tipped to Launch Alongside Redmi Turbo 5 Series, New Wearables
  7. Mrs Deshpande OTT Release Date: Madhuri Dixit’s Psychological Thriller Premieres on This Date
  8. Knives Out Now Streaming on Lionsgate Play: What You Need to Know
  9. The Copenhagen Test OTT Release Date: When and Where to Watch it Online?
  10. Tell Me Softly Out on OTT: Everything You Need to Know About This Spanish Teen Romance Film
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.