Et Tu, MacBook? Unprivileged Keystroke Inference via Built-In IMU Side Channel
a day ago
- Apple MacBooks' built-in IMU can be exploited as a side channel via an IOKit driver without root access.
- The side channel leaks information across three dimensions: keystroke identity, desk surface, and user behavior.
- The BRUTUS attack achieves 89.1% to 97.5% character-level accuracy in key recovery and can reconstruct sentences with 100% accuracy.
- Unprivileged access to IMU data poses a serious security threat, highlighting the need for stricter access controls.