Researchers have discovered a new vulnerability, called iLeakage, that affects Apple devices and allows attackers to steal sensitive information, such as passwords and emails, through a speculative execution side channel attack on the Safari web browser. The attack exploits the CPU's microarchitecture and can be used to recover secrets from popular high-value targets. The vulnerability has been mitigated in Safari 17.2, which ships with iOS 17.2 and macOS 14.2. Enabling Lockdown Mode or disabling JavaScript can also mitigate the attack, but may have other effects on device behavior.