Thursday, 1 May 2025
30.1 C
Singapore
35.6 C
Thailand
26.4 C
Indonesia
28.8 C
Philippines

Apple silicon vulnerability exposes encryption keys

Discover the recent vulnerability in Apple's M-series chips that allows encryption keys to leak and learn how to protect your device.

International researchers have unearthed a significant vulnerability in Apple’s M-series chips, which can leak encryption keys. This flaw, embedded within the chip’s microarchitectural design, cannot be patched traditionally. Instead, software-based mitigation strategies are necessary, potentially hampering performance. The technical nature of this discovery is best understood by delving into the detailed report by Ars Technica, but a simplified explanation is provided here for clarity.

Understanding the GoFetch attack

The crux of the issue lies in Apple Silicon’s data memory-dependent prefetcher (DMP). This component predicts which memory addresses will likely be needed by running code, enhancing efficiency. However, this predictive mechanism can be manipulated to unveil sensitive data, including encryption keys, through an attack dubbed GoFetch. The researchers’ groundbreaking insight revealed that while the DMP typically only dereferences pointers, attackers can craft inputs that, combined with cryptographic secrets, result in an intermediate state mimicking a pointer under specific conditions. This vulnerability enables the extraction of partial or complete information about the cryptographic secret, undermining the security of constant-time swap primitives and various cryptographic implementations designed to resist chosen-input attacks.

Historical context and mitigation

Interestingly, this is not the first instance of a DMP-related flaw in Apple Silicon; a similar vulnerability, the Augury flaw, was identified in 2022. Although the recent discovery may raise concerns, the practical risk is considered low. Gaining system access and the time required for an attack are significant barriers. Extracting a 2048-bit RSA key took the researchers just under an hour, whereas obtaining a 2048-bit Diffie-Hellman key took over two hours, and a Dilithium-2 key took more than ten hours.

Protecting your devices

Adhering to basic security practices is advisable for users seeking to safeguard their devices against such vulnerabilities. Keeping macOS Gatekeeper enabled and avoiding the installation of apps from unknown sources are essential steps in maintaining security.

In summary, while discovering this flaw in Apple’s M-series chips highlights potential security concerns, the immediate risk to users remains low, thanks to the demanding requirements for executing such an attack. Nonetheless, awareness and adherence to recommended security measures are crucial for protection.

Hot this week

Nintendo pop-up store and Mario Kart fun return to Jewel Changi Airport

Experience the magic of Nintendo at Jewel Changi Airport with the return of the Pop-Up Store and the exciting Mario Kart Jewel Circuit Challenge!

Google Play loses nearly half its apps since early 2024

Due to stricter rules and quality control changes, Google Play lost nearly half its apps in 2024, dropping from 3.4M to 1.8M.

Verizon report reveals 80% of APAC breaches caused by system intrusions

System intrusions caused 80% of data breaches in APAC, according to Verizon’s 2025 report, with malware and ransomware threats on the rise.

Startups fight back against Cluely’s AI cheating tool with detection software

Startups fight back against AI cheating tool Cluely with new detection software, while Cluely hints at future smart glasses and AI hardware.

Razer launches Pro Click V2 and V2 Vertical Mice: Blending gaming and productivity

Razer's new Pro Click V2 and V2 Vertical mice offer gaming precision and ergonomic comfort, with AI prompt access and long battery life, available now!

Garmin introduces Instinct 3 – Tactical Edition smartwatch in Singapore

Garmin launches the Instinct 3 – Tactical Edition in Singapore, combining durability, tactical tools, health tracking, and solar power.

Verizon report reveals 80% of APAC breaches caused by system intrusions

System intrusions caused 80% of data breaches in APAC, according to Verizon’s 2025 report, with malware and ransomware threats on the rise.

Asia Pacific’s AI progress held back by network limitations, says IDC report

APAC’s AI ambitions are limited by poor network infrastructure, with 94% of firms saying their networks can’t support large-scale AI projects.

Borderlands 4 reveals first look at new gameplay and characters

Borderlands 4 reveals extended gameplay, two new Vault Hunters, and co-op features ahead of its launch on 12 September 2025.

Related Articles

Popular Categories