New "GoFetch" Attack on Apple Silicon CPUs Exposes Crypto Keys

General News

Summary

A recent revelation by a consortium of researchers from various US universities has shed light on a novel method of breaching the security of Apple Silicon CPUs, potentially exposing sensitive cryptographic keys. Termed the "GoFetch" attack, this exploit targets a microarchitectural vulnerability in Apple CPU systems, facilitating the extraction of encryption keys used in cryptographic operations. It capitalizes on a hardware optimization feature known as the data memory-dependent prefetcher (DMP), designed to enhance system performance by preemptively fetching memory addresses from program content. The researchers discovered that by employing meticulously crafted inputs for cryptographic operations, they could exploit the behavior of the DMP to infer secret keys incrementally. Several cryptographic protocols were found to be vulnerable to GoFetch attacks, including OpenSSL Diffie-Hellman Key Exchange, Go RSA, and post-quantum algorithms such as CRYSTALS-Kyber and CRYSTALS-Dilithium.

Classifications

industries
Entertainment
applications
Customer Service & Support

AskAI Classifications

Labels
Cybersecurity Software Anti-Malware Software SaaS Security

Linked Companies

EnigmaSoft
$1M to $5M
Apple Inc.
$1B+