Patchless Apple M-Chip Vulnerability Allows Cryptography Bypass
ID: 92813596-61f1-5c73-bec6-cc3b7f2ee3d0
STIX ID: report--92813596-61f1-5c73-bec6-cc3b7f2ee3d0
Feed Name: Dark Reading
A research team disclosed a microarchitectural timing side-channel called "GoFetch" that leverages data memory-dependent prefetchers (DMP) in Apple M-series and Intel Raptor Lake CPUs to extract cryptographic keys — including from OpenSSL Diffie-Hellman, Go RSA, and even CRYSTALS Dilithium/Kyber. Apple published a developer workaround that enables data-independent timing (DIT) on M3 chips; M1/M2 require software-level mitigations. The PoC demonstrates real risk to cryptographic secrecy across hardware/software stacks and suggests similar behaviors may exist on other processors.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
