A recent vulnerability discovered in Apple allows hackers to recover encryption keys from Macs, academic researchers said in a paper published Thursday.

The vulnerability, a side channel that allows end-to-end key extraction when running applications on Apple chips that use widely used encryption protocols, is not immediately patched, as it is due to the microarchitectural design of the silicon. Instead, it can only be addressed by strengthening defenses in third-party encryption software, which can significantly impact the performance of the M series when performing cryptographic operations, especially in the previous generations of M1 and M2. The exploitation of this vulnerability occurs when the specific cryptographic operation and the malicious application are running on the same processor cluster, with normal user system privileges.
See also: Snapdragon 8 Gen 4: Supports faster RAM chip that outperforms Apple's A18 Pro
The threat lies in the data collector that relies on the chip's data memory. This prefetcher is a hardware optimization that predicts the memory addresses of data that executing code may access in the future. In this way, by loading data into the CPU before it is actually needed, the DMP (Data Movement Predictor), as it is commonly referred to, reduces the latency between main memory and the CPU, which is a common bottleneck in modern computing. DMPs are a relatively recent phenomenon that only exists in M-series chips and Intel, while older forms of prefetchers have been common for many years.
Security experts have long known that classic prefetchers open a side door through which malicious processes can detect and explore to obtain secret keys from cryptographic operations. This vulnerability arises from prefetchers’ predictions based on previous access patterns, which can cause state changes that attackers can exploit to leak information. In response, cryptographic engineers have invented constant-time programming, an approach that ensures that all operations take the same amount of time to complete, regardless of their operands. This keeps code safe from secret accesses and memory structures.
The achievement of the new research is that it reveals a behavior of DMPs that had previously been overlooked in the Apple kernel. In some cases, DMPs confuse the contents of memory, such as the underlying hardware, with the value of the pointer used to load other data. As a result, the DMP often reads the data and tries to treat it as an address for accessing memory. This “dereferencing” of “pointers” – meaning reading data and leaking it through a side channel – is a clear violation of the constant-time paradigm.
This isn’t the first time researchers have detected threats lurking in Apple’s DMPs. The optimization first surfaced in a 2022 study, which discovered a previously unknown “pointer-chasing DMP” in both Apple’s M1 chip and A14 Bionic chip for iPhones. New research by academics led to Augury, an attack that exposed a memory-side channel where pointers were leaked. Ultimately, Augury struggled to combine data and addresses using fixed-time practices, suggesting that the DMP may not have been such a big threat.
"GoFetch demonstrates that DMP is much more aggressive than we expected and therefore poses a much greater risk," the GoFetch authors state on their website. "Specifically, we observe that any value loaded into memory is vulnerable to disclosure. This allows us to bypass many of Augury's limitations and perform end-to-end attacks on the code in real time.".
Like other CPU microarchitectures, GoFetch is notoriously difficult to patch using simple methods. The responsibility for mitigating the impact of its vulnerability lies with developers who develop software for Apple products. For developers of encryption software that runs on Apple's M1 and M2 chips, it means they have to implement additional security measures, which almost always have a significant impact on performance.
Read more: Apple Reveals Everything About Its New MM1 AI Model
One of the most effective security methods, known as “ciphertext blinding,” is a prime example. The blinding process works by adding or removing masks to sensitive values before or after they are stored in memory. This essentially prevents a hacker from retrieving them and prevents GoFetch attacks. According to researchers, this protection method, while effective for the algorithm, often proves to be expensive, and can double the computing resources required in some cases, such as in Diffie-Hellman key exchanges.
An alternative approach is to implement cryptographic operations on the previously mentioned performance cores, which are commonly known as Icestorm cores and do not contain DMP. An alternative approach is to execute the cryptographic code on these cores. Although this method is not ideal, as unexpected changes may add DMP functionality to the performance, executing cryptographic operations there can increase the time required to complete operations by a non-trivial margin. The researchers document several ad-hoc approaches for defenses, although these are equally problematic.
The DMP in the M3, Apple's newest chip, includes a special bit that allows developers to disable its functionality. Researchers still don't fully understand what the implications of disabling this performance enhancement would be. (It has been noted that the DMP found in Intel's Raptor Lake processors does not leak the same cryptographic information. Additionally, setting a special DOIT bit also effectively disables DMP.)
Readers should remember that potential penalties will only apply when the software in question performs specific cryptographic functions. In browsers and many other types of applications, the performance cost may not be apparent.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
“We believe that the optimal solution would be to extend the hardware-software contract to take DMP into account,” the researchers note. “The hardware should provide at least a method for selectively disabling DMP when running safety-. This is unprecedented in the field. For example, Intel’s DOIT extensions provide for disabling DMP via an ISA extension. In the long term, it would be desirable to control DMP in greater detail, for example, limiting operation to only apply to specific buffers or certain non-sensitive memory regions.”

Concerned users should check for GoFetch mitigation updates available for macOS software that uses any of the four cryptographic protocols that have been reported as vulnerable. From the abundance of attention, we can assume that other cryptographic protocols are likely to be vulnerable as well, at least for now.
See more: Walmart: Started selling MacBook Air with M1 chip
“Unfortunately, assessing whether an application is vulnerable requires cryptanalysis and code inspection to understand how intermediate values can be modified to mimic pointers in a way that leaks secrets,” the researchers. “This process requires manual processing and is time-consuming, and does not preclude other attack methods.”
Source: arstechnica.com
