Apple Silicon Vulnerability Allows Hackers to Extract Encryption Keys - MacRumorsOpen MenuShow RoundupsShow Forums menuVisit ForumsOpen Sidebar
Skip to Content

Apple Silicon Vulnerability Allows Hackers to Extract Encryption Keys

An unpatchable vulnerability has been discovered in Apple's M-series chips that allows attackers to extract secret encryption keys from Macs under certain conditions, according to a newly published academic research paper (via ArsTechnica).

m1 vs m2 air feature toned down
Named "GoFetch," the type of cyber attack described involves Data Memory-Dependent Prefetchers (DMPs), which try to predict what data the computer will need next and retrieve it in advance. This is meant to make processing faster, but it can unintentionally reveal information about what the computer is doing.

The paper finds that DMPs, especially the ones in Apple's processors, pose a significant threat to the security provided by constant-time programming models, which are used to write programs so that they take the same amount of time to run, no matter what data they're dealing with.

The constant-time programming model is meant to protect against side-channel attacks, or types of attacks where someone can gain sensitive information from a computer system without directly accessing it (by observing certain patterns, for example). The idea is that if all operations take the same amount of time, there's less for an attacker to observe and exploit.

However, the paper finds that DMPs, particularly in Apple silicon, can leak information even if the program is designed not to reveal any patterns in how it accesses memory. The new research finds that the DMPs can sometimes confuse memory content, which causes it to treat the data as an address to perform memory access, which goes against the constant-time model.

The authors present GoFetch as a new type of attack that can exploit this vulnerability in DMPs to extract encryption keys from secure software. The attack works against some popular encryption algorithms that are thought to be resistant to side-channel attacks, including both traditional (e.g. OpenSSL Diffie-Hellman Key Exchange, Go RSA decryption) and post-quantum (e.g. CRYSTALS-Kyber and CRYSTALS-Dilithium) cryptographic methods.

In an email to ArsTechnica, the authors explained:

Prefetchers usually look at addresses of accessed data (ignoring values of accessed data) and try to guess future addresses that might be useful. The DMP is different in this sense as in addition to addresses it also uses the data values in order to make predictions (predict addresses to go to and prefetch). In particular, if a data value "looks like" a pointer, it will be treated as an "address" (where in fact it's actually not!) and the data from this "address" will be brought to the cache. The arrival of this address into the cache is visible, leaking over cache side channels.

Our attack exploits this fact. We cannot leak encryption keys directly, but what we can do is manipulate intermediate data inside the encryption algorithm to look like a pointer via a chosen input attack. The DMP then sees that the data value "looks like" an address, and brings the data from this "address" into the cache, which leaks the "address." We don't care about the data value being prefetched, but the fact that the intermediate data looked like an address is visible via a cache channel and is sufficient to reveal the secret key over time.

In summary, the paper shows that the DMP feature in Apple silicon CPUs could be used to bypass security measures in cryptography software that were thought to protect against such leaks, potentially allowing attackers to access sensitive information, such as a 2048-bit RSA key, in some cases in less than an hour.

According to the authors, the flaw in Apple's chips cannot be patched directly. Instead, the attack vector can only be reduced by building defenses into third-party cryptographic software that could result in an extreme performance degradation when executing the cryptographic operations, particularly on the earlier M1 and M2 chips. The DMP on the M3, Apple's latest chip, has a special bit that developers can invoke to disable it, but the researchers aren't yet sure what kind of penalty will occur when this performance optimization is turned off.

As ArsTechnica notes, this isn't the first time researchers have identified threats in Apple DMPs. Research documented in 2022 discovered one such threat in both the ‌M1‌ and Apple's A14 Bionic chip for iPhones, which resulted in the "Augury" attack. However, this attack was ultimately unable to extract the sensitive data when constant-time practices were used.

"GoFetch shows that the DMP is significantly more aggressive than previously thought and thus poses a much greater security risk," the researchers claim on their website. "Specifically, we find that any value loaded from memory is a candidate for being dereferenced (literally!). This allows us to sidestep many of Augury's limitations and demonstrate end-to-end attacks on real constant-time code."

DMP-style attacks are not common, and the researchers informed Apple of the vulnerability in December 2023. Users concerned about the vulnerability are advised to check for GoFetch mitigation updates that become available in future macOS updates for any of the encryption protocols known to be vulnerable. Apple representatives declined to comment on the record when ArsTechnica asked about the paper.

Popular Stories

m6 a20 pro chips

iPhone 18 Pro: Everything M6 Tells Us About the A20 Chip

Saturday September 5, 2026 9:00 am PDT by
Apple announced the M6 chip last week, just ahead of its September iPhone event, providing the clearest indication yet of what the A20 will bring to the iPhone 18 lineup. Apple silicon generations share much of their architecture across the A-series and the M-series, so a new A-series chip normally functions as a partial preview of the M-series chip that follows it. This year the order...
a20 pro chip

Apple Unveils A20 Pro as First 2nm Smartphone Chip

Wednesday September 9, 2026 10:22 am PDT by
Apple today revealed the A20 Pro chip in the iPhone 18 Pro and iPhone 18 Pro Max, built on a brand new architecture using 2nm process technology. Apple described the A20 Pro as "an exceptional chip that sets a new bar for mobile computing." The chip has a 6-core CPU design with two new super cores that Apple says are up to 20% faster, calling them "desktop class" and "the fastest in any...
apple lock security bug vulnerability fix privacy

Apple Still Working on Anti-Snatching Feature That Locks Stolen iPhones

Tuesday September 22, 2026 4:44 am PDT by
New references in the latest iOS 27.2 beta show that Apple continues to develop a new feature which will lock your iPhone if it's snatched from your hand by a thief. As previously reported, the feature will use the gyroscope, accelerometer, and other sensors to determine when an iPhone has been grabbed. It'll also rely on a paired Apple Watch to detect when the iPhone has suddenly moved...

Top Rated Comments

33 months ago
This kind of vulnerability is bad - future hardware revisions should solve it and mitigations should be put into place. However, glossing over the paper, this currently does not seem like a big threat to most users:

Emulating realistic attack scenarios, we assume that ct-swap runs in a victim process, separate from the attacker’s address space. We assume a simple but common protocol between victim and attacker, where the victim takes input from the attacker to populate the ct-swap’s a and b arrays and then executes ct-swap.

So, it assumes that not only has the attacker has a process running on a victim's machine, but that it can also feed input directly to the victim process. However, if a malicious actor already has a local process running with user privileges, there are so many possible attack vectors, that it's also often game over before this vulnerability. If you only install trusted software, you should be pretty safe.

What made Meltdown/Spectre so devastating on Intel CPUs is that they allowed snooping information without communication with the victim process and that e.g. Linux is used on many multi-tenant machines. So there is ample opportunity to eavesdrop on other people's machines.

It's a bit sad that Ars did not qualify the research further, because if you read the headline and article, it's as if the sky is falling on Apple Silicon CPUs. But (not surprisingly) it's not.
Score: 68 Votes (Like | Disagree)
brijazz Avatar
33 months ago
Still better than updating to 14.4 ;)
Score: 33 Votes (Like | Disagree)
33 months ago

From Macworld this morning:
[...]
DMP-based attacks aren’t common, and they require a hacker to have physical access to a Mac. So, the best way to prevent an attack is you secure your user account on your Mac with a strong password, and do not let people you don’t know use your Mac. For more information on Mac security, read “;How to know if your Mac has been hacked ('https://www.macworld.com/article/676307/how-to-know-if-your-mac-has-been-hacked.html')” and “How secure is your Mac? ('https://www.macworld.com/article/668710/how-secure-mac.html')” Also consider running an antivirus program on your Mac ('https://www.macworld.com/article/670537/do-macs-need-antivirus.html').
By the way, MacWorld is incorrect here. It does not require physical access. A malicious actor needs to be able to run a process in your machine. This can also be accomplished by tricking the user to install malware, planting malware through vulnerabilities in programs that read untrusted data (web browser, iMessage, etc.).

If you don't install random software from the internet, you should be pretty safe.
Score: 27 Votes (Like | Disagree)
hovscorpion12 Avatar
33 months ago
Genuine question. Does this “exploit“ actually have an effect on users? Or this for specific individuals?
Score: 25 Votes (Like | Disagree)
33 months ago
This can be fixed by upgrading to M5.
Score: 23 Votes (Like | Disagree)
hovscorpion12 Avatar
33 months ago

Wonder how long Apple has known about this? I think we can safely assume based on past experience that Apple did nothing, hoping the public would never know.
The devs posted they informed Apple in Dec 2023.
Score: 21 Votes (Like | Disagree)
Latest Stories
AT&T Acknowledges iPhone 18 Pro Max Issues: 'Update Immediately'
AT&T Acknowledges iPhone 18 Pro Max Issues: 'Update Immediately'
3 hours ago
New 'AirFly Drive' Accessory Turns Wired CarPlay Into Wireless CarPlay
New 'AirFly Drive' Accessory Turns Wired CarPlay Into Wireless CarPlay
9 hours ago
Apple Shares Photos Shot on iPhone Duo
Apple Shares Photos Shot on iPhone Duo
10 hours ago
Apple Says iPhone Duo Has Replaceable 'Cover Layer'
Apple Says iPhone Duo Has Replaceable 'Cover Layer'
11 hours ago
Apple's Smart Home Camera Will Apparently Have 'No Video Recording'
Apple's Smart Home Camera Will Apparently Have 'No Video Recording'
13 hours ago
Apple TV Just Updated Its Selection of 'Bonus' Movies
Apple TV Just Updated Its Selection of 'Bonus' Movies
15 hours ago
iPhone 18 Pro Colors Buyer's Guide: Which Should You Choose?
iPhone 18 Pro Colors Buyer's Guide: Which Should You Choose?
15 hours ago
Early Prime Big Deal Days: Best Discounts on Accessories, TVs, and More at Amazon
Early Prime Big Deal Days: Best Discounts on Accessories, TVs, and More at Amazon
15 hours ago
MacBook Pro With OLED Touch Screen Rumored to Launch in October or November
MacBook Pro With OLED Touch Screen Rumored to Launch in October or November
16 hours ago
Apple's All-New Home Hub Rumored to Launch in These Four Colors
Apple's All-New Home Hub Rumored to Launch in These Four Colors
17 hours ago
iPhone 18 Pro Aperture Control Goes Fully Manual in Halide 3.2
iPhone 18 Pro Aperture Control Goes Fully Manual in Halide 3.2
18 hours ago
Apple Stores Receive 'Do Not Open' Boxes Ahead of Smart Home Products Launch
Apple Stores Receive 'Do Not Open' Boxes Ahead of Smart Home Products Launch
19 hours ago
iPhone 18 Pro Sales Jump in China Ahead of iPhone Duo Launch
iPhone 18 Pro Sales Jump in China Ahead of iPhone Duo Launch
19 hours ago
Apple TV Still Down for Some Users Following Apple Services Outage
Apple TV Still Down for Some Users Following Apple Services Outage
20 hours ago
PSA: Apple Mail on Mac May Stop Syncing Microsoft 365 Accounts Today
PSA: Apple Mail on Mac May Stop Syncing Microsoft 365 Accounts Today
20 hours ago
Apple's Smart Home Hub: Everything We Know So Far
Apple's Smart Home Hub: Everything We Know So Far
1 day ago
Apple's Home Hub Borrows From the iPhone Duo's StandBy Mode
Apple's Home Hub Borrows From the iPhone Duo's StandBy Mode
1 day ago
Apple Invites App Updated With Three New Features
Apple Invites App Updated With Three New Features
2 days ago
Apple Event on October 13?
Apple Event on October 13?
2 days ago
Apple Watch SE 3 vs. Series 12 Buyer's Guide: Which Should You Buy?
Apple Watch SE 3 vs. Series 12 Buyer's Guide: Which Should You Buy?
2 days ago
iPad Mini 8 to Offer These 10 New Features
iPad Mini 8 to Offer These 10 New Features
2 days ago
DoorDash Unveils AI Food Ordering Through Apple's Messages App
DoorDash Unveils AI Food Ordering Through Apple's Messages App
2 days ago
Amazon Takes Up to $150 Off Select M5 MacBook Air Models
Amazon Takes Up to $150 Off Select M5 MacBook Air Models
2 days ago
Apple Still Plans to Release a New Full-Sized HomePod
Apple Still Plans to Release a New Full-Sized HomePod
2 days ago
Apple Working to Expand HomeKit
Apple Working to Expand HomeKit
2 days ago
Apple Smart Home Hub to Feature iMac G4-Style Design
Apple Smart Home Hub to Feature iMac G4-Style Design
2 days ago
Three New Apple Smart Home Products Coming on October 13
Three New Apple Smart Home Products Coming on October 13
2 days ago
Apple Pay Now Available in India With Axis Bank Cards
Apple Pay Now Available in India With Axis Bank Cards
2 days ago
OpenAI Launches Always-On 'Dots' Agents to Rival Meta's Muse
OpenAI Launches Always-On 'Dots' Agents to Rival Meta's Muse
2 days ago
AirPods 5 Teardown: Batteries Removable, Case Still Tough
AirPods 5 Teardown: Batteries Removable, Case Still Tough
2 days ago

🔗 Related Apple News & Rumors

Stay updated with the latest Apple ecosystem news and verified rumors