Tuesday, 21 October 2025
28.9 C
Singapore
24.3 C
Thailand
21.6 C
Indonesia
28.5 C
Philippines

Apple silicon vulnerability exposes encryption keys

Discover the recent vulnerability in Apple's M-series chips that allows encryption keys to leak and learn how to protect your device.

International researchers have unearthed a significant vulnerability in Apple’s M-series chips, which can leak encryption keys. This flaw, embedded within the chip’s microarchitectural design, cannot be patched traditionally. Instead, software-based mitigation strategies are necessary, potentially hampering performance. The technical nature of this discovery is best understood by delving into the detailed report by Ars Technica, but a simplified explanation is provided here for clarity.

Understanding the GoFetch attack

The crux of the issue lies in Apple Silicon’s data memory-dependent prefetcher (DMP). This component predicts which memory addresses will likely be needed by running code, enhancing efficiency. However, this predictive mechanism can be manipulated to unveil sensitive data, including encryption keys, through an attack dubbed GoFetch. The researchers’ groundbreaking insight revealed that while the DMP typically only dereferences pointers, attackers can craft inputs that, combined with cryptographic secrets, result in an intermediate state mimicking a pointer under specific conditions. This vulnerability enables the extraction of partial or complete information about the cryptographic secret, undermining the security of constant-time swap primitives and various cryptographic implementations designed to resist chosen-input attacks.

Historical context and mitigation

Interestingly, this is not the first instance of a DMP-related flaw in Apple Silicon; a similar vulnerability, the Augury flaw, was identified in 2022. Although the recent discovery may raise concerns, the practical risk is considered low. Gaining system access and the time required for an attack are significant barriers. Extracting a 2048-bit RSA key took the researchers just under an hour, whereas obtaining a 2048-bit Diffie-Hellman key took over two hours, and a Dilithium-2 key took more than ten hours.

Protecting your devices

Adhering to basic security practices is advisable for users seeking to safeguard their devices against such vulnerabilities. Keeping macOS Gatekeeper enabled and avoiding the installation of apps from unknown sources are essential steps in maintaining security.

In summary, while discovering this flaw in Apple’s M-series chips highlights potential security concerns, the immediate risk to users remains low, thanks to the demanding requirements for executing such an attack. Nonetheless, awareness and adherence to recommended security measures are crucial for protection.

Hot this week

TeamViewer integrates AI-driven workplace solutions with Salesforce Agentforce IT Service

TeamViewer integrates AI-powered DEX and remote connectivity with Salesforce Agentforce IT Service to boost IT efficiency and reliability.

Salesforce and OpenAI join forces to transform enterprise work and commerce

Salesforce and OpenAI are partnering to integrate frontier AI and CRM tools, transforming enterprise workflows and conversational commerce.

Apple is expected to unveil a new MacBook powered by the M5 chip

Apple is expected to unveil a new MacBook with its powerful M5 chip, following a teaser hinting at an upcoming product launch.

Meta accelerates AI innovation in Singapore with Llama Incubator Program Demo Day

Meta’s Llama Incubator Demo Day highlights its push to support open-source AI innovation and strengthen Singapore’s digital economy.

Nintendo accelerates Switch 2 production as demand remains strong

Nintendo ramps up Switch 2 production to meet soaring demand, aiming to sell up to 25 million units by March 2026.

Oura redesigns app with enhanced stress tracking and hypertension study

Oura unveils redesigned app with advanced stress tracking and begins FDA-backed study to develop early hypertension detection features.

Shadow of the Colossus turns 20: Exploring the moral depth of gaming’s quietest hero

Shadow of the Colossus marks its 20th anniversary, celebrated for its quiet heroism, moral depth, and enduring emotional power.

Samsung partners with Nvidia to develop custom CPUs and XPUs for AI dominance

Nvidia partners with Samsung to develop custom CPUs and XPUs, expanding its NVLink Fusion ecosystem to strengthen its AI hardware dominance.

NVIDIA unveils first US-made Blackwell wafer as domestic chip production expands

NVIDIA unveils its first US-made Blackwell wafer at TSMC’s Arizona facility, marking a major milestone in domestic AI chip production.

Related Articles