Videos / Defcon / Joseph Ravichandran: PACMAN Attack — Breaking Apple M1 Protections

Joseph Ravichandran: PACMAN Attack — Breaking Apple M1 Protections

Duration: 32min 27sec Type: Presentation (lecture) Playlist: 50 of 146 in Defcon
A DEF CON 30 talk about a novel hardware-software attack on Apple M1 processors. The researcher demonstrates how to bypass Pointer Authentication (PAC), a security feature designed to prevent memory exploitation.

The PACMAN method leverages microarchitectural side channels and speculative execution to brute-force pointer authentication codes without causing system crashes.

The talk includes a practical demonstration of the attack and explains why such vulnerabilities emerge at the intersection of hardware design and software security mechanisms.