An Apple Byte : Serious Apple Chip Vulnerability Discovered

Paul Stradling • March 27, 2024

An Apple Byte : Serious Apple Chip Vulnerability Discovered

US researchers have reported discovering a hardware chip vulnerability inside Apple M1, M2, and M3 silicon chips. The unpatchable ‘GoFetch’ is a microarchitecture vulnerability and side-channel attack that reportedly affects all kinds of encryption algorithms, even the 2,048-bit keys that are hardened to protect against attacks from quantum computers. 


This serious vulnerability renders the security effects of constant-time programming (a side-channel mitigation encryption algorithm) useless. This means that encryption software can be tricked by applications using GoFetch into putting sensitive data into the cache so it can be stolen. 



Pending any fix advice from Apple, users are recommended to use the latest versions of software, and to perform updates regularly. Also, developers of cryptographic libraries should set the DOIT bit and DIT bit bits (disabling the DMP on some CPUs) and to use input blinding (cryptography). Users are also recommended to avoid hardware sharing to help maintain the security of cryptographic protocols.

Protect Your Business During Staff Holidays
By Paul Deaville June 26, 2024
In this next summer security article, and with the summer holiday season upon us, we take a look at the various aspects of protecting your business when your staff are on holiday, offering practical advice and solutions to help you stay secure and efficient while staff are physically away.
Why Microsoft 365 Backup is Essential
By Paul Deaville June 26, 2024
In this article, we look at why, as reliance on cloud services like Microsoft 365 grows, ensuring robust data backup has become a critical component of business security and continuity, then we look at some best practices for your 365 backups.
More Posts