• News/
  • https://www.theregister.com/2024/03/22/hardwarelevel_apple_silicon_vulnerability_can/

Hardware-level vulnerability found in Apple Silicon CPUs

The Register
·
Brandon Vigliarolo
·
Published Mar 22, 2024
·
Updated

A side-channel vulnerability has been found in the architecture of Apple Silicon processors that gives malicious apps the ability to extract cryptographic keys from memory that should be off limits. Dubbed GoFetch by the team that discovered it, the issue stems from how processors equipped with data memory-dependent prefetchers (DMPs) - eg, Arm-compatible Apple Silicon chips, and 13th generation and newer Intel architectures - can end up revealing sensitive information to malware running on a device. For decades a lot of processors have typically used some kind of prefetching to boost their performance: These usually work by predicting what data the currently running program will need next from, say, system memory and automatically bringing that information into a cache within the processor from DRAM so it's ready for near-immediate use. The location of the data to prefetch could be predicted by noticing that a CPU core is accessing information in a certain pattern and then following that pattern ahead of execution. DMPs try to be a bit smarter by predicting what will be fetched next from the contents of memory. For instance, if it looks like the processor is preparing to fetch some data from a location based on what looks like a memory address at another location – think linked lists and the like in which one block of data has a pointer to another – the DMP may begin bringing into the cache that next data. But that isn't without its problems: A vulnerable DMP can be manipula...

Read full article

Affected Software

4 affected components
Apple Silicon M1
Apple Silicon M2
Apple Silicon M3
Intel 13th Gen Raptor Lake microarchitecture
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article reports on a hardware-level vulnerability found in Apple Silicon CPUs that can be exploited by malicious applications.

2

What is the vulnerability called?

The vulnerability is called GoFetch, which allows unauthorized access to cryptographic keys stored in memory.

3

What security implications are discussed regarding this vulnerability?

The vulnerability poses a significant risk as it allows attackers to extract sensitive cryptographic keys, potentially compromising user data and security.

4

Which products are affected by this vulnerability?

The affected products include Apple’s Silicon M1, Silicon M2, Silicon M3, and Intel's 13th Gen Raptor Lake microarchitecture.

5

Who discovered the vulnerability and how is it characterized?

The vulnerability was discovered by a security team and is characterized as a side-channel vulnerability in the architecture of Apple Silicon processors.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203