Bitget App
Trade smarter
Buy cryptoMarketsTradeFuturesEarnWeb3SquareMore
Trade
Spot
Buy and sell crypto with ease
Margin
Amplify your capital and maximize fund efficiency
Onchain
Going Onchain, without going Onchain!
Convert & block trade
Convert crypto with one click and zero fees
Explore
Launchhub
Gain the edge early and start winning
Copy
Copy elite trader with one click
Bots
Simple, fast, and reliable AI trading bot
Trade
USDT-M Futures
Futures settled in USDT
USDC-M Futures
Futures settled in USDC
Coin-M Futures
Futures settled in cryptocurrencies
Explore
Futures guide
A beginner-to-advanced journey in futures trading
Futures promotions
Generous rewards await
Overview
A variety of products to grow your assets
Simple Earn
Deposit and withdraw anytime to earn flexible returns with zero risk
On-chain Earn
Earn profits daily without risking principal
Structured Earn
Robust financial innovation to navigate market swings
VIP and Wealth Management
Premium services for smart wealth management
Loans
Flexible borrowing with high fund security
Apple Users Beware: Reported Flaw Exposes Mac Users Crypto Private Keys

Apple Users Beware: Reported Flaw Exposes Mac Users Crypto Private Keys

CryptopotatoCryptopotato2024/03/23 05:55
By:Chayanika DekaMore posts by this author

Apple’s hardware security faces a critical flaw that allows malicious entities to extract sensitive information.

A recent study has raised alarms after identifying a vulnerability in Apple’s M-series chips that has the potential to enable hackers to retrieve the cryptographic private keys of Mac users.

In the absence of a direct resolution, the other method suggested by researchers may drastically hamper performance.

Apple M-Series Chips Susceptible to Key Extraction

The vulnerability in question functions as a side channel, thereby permitting the extraction of end-to-end keys when Apple chips execute implementations of commonly employed cryptographic protocols. Due to its origin in the microarchitectural structure of the silicon, direct patching is not feasible, unlike traditional vulnerabilities.

Instead, the report highlighted a fix that relies on integrating defenses into third-party cryptographic software. However, this approach may significantly, “degrade” the performance of M-series chips during cryptographic tasks, especially evident in earlier generations like M1 and M2.

The researchers also added that the exploitation of the vulnerability occurs when both the targeted cryptographic operation and a malicious application, operating with standard user system privileges, are processed on the same CPU cluster.

“Our key insight is that while the DMP only dereferences pointers, an attacker can craft program inputs so that when those inputs mix with cryptographic secrets, the resulting intermediate state can be engineered to look like a pointer if and only if the secret satisfies an attacker-chosen predicate.”

The latest research sheds light on, what is being toouted as, an overlooked phenomenon regarding DMPs within Apple silicon. In certain cases, these DMPs misinterpret memory content, including critical key material, as the pointer value utilized for loading other data. As a result, the DMP frequently accesses and interprets this data as an address, leading to memory access attempts, the team of researchers explained.

This process, known as “dereferencing” of “pointers,” entails reading data and inadvertently leaking it through a side channel, representing a clear breach of the constant-time paradigm.

GoFetch

The researchers identified this hack as a “GoFetch” exploit while explaining that it operates on the same user privileges as most third-party applications, exploiting vulnerabilities in clusters of M-series chips. It affects classical and quantum-resistant encryption algorithms alike, with extraction times varying from minutes to hours depending on the key size.

Despite previous knowledge of similar threats, the researchers said that GoFetch demonstrates a more aggressive behavior in Apple’s chips, posing a significant security risk.

You Might Also Like:

  • Fake Rabby Wallet Approved on App Store Before Real One
  • Here's How Scammers Have Improved Their Tactics in Address Poisoning Attacks
  • Mac Users Beware: Kaspersky Alerts About a Malicious Exploit Targeting Your Crypto Wallets
0

Disclaimer: The content of this article solely reflects the author's opinion and does not represent the platform in any capacity. This article is not intended to serve as a reference for making investment decisions.

PoolX: Earn new token airdrops
Lock your assets and earn 10%+ APR
Lock now!

You may also like

New spot margin trading pair — BARD/USDT!

Bitget Announcement2025/09/19 07:28

BTC/ETH VIP Earn Ultimate Carnival is officially here!

Bitget Announcement2025/09/18 07:12

New spot margin trading pair — FLOCK/USDT!

Bitget Announcement2025/09/18 06:55

0GUSDT now launched for pre-market futures trading

Bitget Announcement2025/09/18 05:39