Hardware-level Apple Silicon vulnerability can leak cryptographic keys
ID: da6a6a55-8dbc-585a-b066-d1a1da7a5b9e
STIX ID: report--da6a6a55-8dbc-585a-b066-d1a1da7a5b9e
Feed Name: The Register (Security)
A research team disclosed "GoFetch," a side-channel vulnerability in data memory-dependent prefetchers (DMPs) on Apple Silicon (M1, base M2, M3 tested) and some Intel architectures that allows unprivileged local code to induce speculative dereferences and use cache-timing analysis to recover long-term cryptographic keys; the paper shows practical key-extraction attacks against OpenSSL DH/RSA and post-quantum CRYSTALS-Kyber/Dilithium. Mitigations include disabling DMP where supported or hardening cryptographic implementations (with performance trade-offs); Apple and Intel guidance and hardware differences affect risk and remediation options.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
