New GoFetch attack on Apple Silicon CPUs can steal crypto keys
ID: 0081872b-5d0c-5d4c-bf7b-a55bca91db46
STIX ID: report--0081872b-5d0c-5d4c-bf7b-a55bca91db46
Feed Name: Bleeping Computer
**Executive Summary:** GoFetch is a newly disclosed side-channel attack against Apple M1/M2/M3 processors that abuses data memory-dependent prefetchers (DMP) to leak secret cryptographic keys from cache, enabling recovery of keys for algorithms such as OpenSSL Diffie-Hellman, Go RSA, CRYSTALS Kyber, and Dilithium; the flaw stems from DMP behavior that violates constant-time programming assumptions, hardware fixes are not possible for impacted chips, and software mitigations incur performance costs.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
