NewsBytes
    Hindi Tamil Telugu
    More
    In the news
    Narendra Modi
    Amit Shah
    Box Office Collection
    Bharatiya Janata Party (BJP)
    OTT releases
    Hindi Tamil Telugu
    NewsBytes
    User Placeholder

    Hi,

    Logout


    India Business World Politics Sports Technology Entertainment Auto Lifestyle Inspirational Career Bengaluru Delhi Mumbai Visual Stories Find Cricket Statistics Phones Reviews Fitness Bands Reviews Speakers Reviews

    Download Android App

    Follow us on
    • Facebook
    • Twitter
    • Linkedin
     
    Home / News / Technology News / Chip-level vulnerability in Apple Macs could cause massive data leak
    Next Article
    Chip-level vulnerability in Apple Macs could cause massive data leak
    Researchers have exposed the chip encryption flaw

    Chip-level vulnerability in Apple Macs could cause massive data leak

    By Akash Pandey
    Mar 23, 2024
    11:59 am
    What's the story

    A group of university-based security researchers has discovered a chip-level vulnerability in Mac computers with Apple Silicon. This flaw could potentially enable hackers to sidestep the computer's encryption and gain access to its security keys, thus revealing private data. However, exploiting this vulnerability is not straightforward. It involves bypassing Apple's Gatekeeper protections and installing a malicious app that needs to run for up to 10 hours.

    Root of the exploit

    It originates in a part of M-series chips

    As per the researchers, the vulnerability lies within a component of Apple's M-series chips, called Data Memory-Dependent Prefetchers (DMPs). These DMPs boost processor efficiency by proactively caching data, interpreting data patterns as instructions to predict which information they need to access next. This feature significantly contributes to the high-speed performance that Apple Silicon is known for.

    Discovery

    Researchers uncover DMP's potential to circumvent encryption

    The researchers found that attackers could exploit DMP to circumvent encryption. They clarified, "Through new reverse engineering, we find that the DMP activates on behalf of potentially any program and attempts to dereference any data brought into cache that resembles a pointer." This behavior exposes a substantial amount of program data, as pointers are essentially addresses indicating where specific data can be located.

    Insights

    Researchers created GoFetch to illustrate DMP vulnerability

    In their research paper, the team noted that "the security threat from DMPs is significantly worse than previously thought," and demonstrated "the first end-to-end attacks on security-critical software using the Apple M-series DMP." The researchers were able to create an attack named GoFetch, which can access a Mac's secure data without needing root access. This app exploits the vulnerability in Apple's M-series chips to bypass encryption and gain access to private data.

    The mechanics

    How GoFetch exploits M-series chip clusters

    Dan Goodin, Security Editor from Ars Technica has shed light on how GoFetch operates. He explained, "M-series chips are divided into what are known as clusters. The M1, for example, has two clusters: one containing four efficiency cores and the other four performance cores." "As long as the GoFetch app and the targeted cryptography app are running on the same performance cluster—even when on separate cores within that cluster — GoFetch can mine enough secrets to leak a secret key."

    Facebook
    Whatsapp
    Twitter
    Linkedin
    Related News
    Latest
    Apple
    Apple MacBook
    macOS

    Latest

    Karen Pittman bids farewell to Max's 'And Just Like That' Sex And The City
    Nissan reveals 2025 Kicks SUV ahead of first public appearance Nissan
    Cash-for-query row: CBI searches places linked to TMC's Mahua Moitra Mahua Moitra
    WhatsApp to introduce 'Ask Meta AI' feature: How it works  WhatsApp

    Apple

    Steve Jobs' autographed business card sells for $180,000 at auction Steve Jobs
    How Apple's lock-in problem led to antitrust lawsuit by DOJ US Department of Justice
    US Justice Department initiates antitrust lawsuit against Apple over CarPlay US Department of Justice
    US government initiates antitrust lawsuit against Apple: Key takeaways US Department of Justice

    Apple MacBook

    Apple reportedly developing foldable MacBook with 20.3-inch screen  Apple
    Apple to announce new iPads, MacBook models this month Apple
    Apple's high-end iPad with OLED screen to debut in 2024  Apple
    Apple MacBook with in-house cellular modem may launch in 2028 Apple

    macOS

    iOS 18, macOS 15 bringing new features to Freeform app Apple
    Microsoft introduces Windows app for iPhone, iPad, Macs, and PCs Microsoft
    WhatsApp group video calling on Mac: A step-by-step guide WhatsApp
    MacBook Air 15-inch now available in India: Should you buy Apple
    Next Article
    Indian Premier League (IPL) Celebrity Hollywood Bollywood UEFA Champions League Tennis Football Smartphones Cryptocurrency Upcoming Movies Premier League Cricket News Latest automobiles Latest Cars Upcoming Cars Latest Bikes Upcoming Tablets
    About Us Privacy Policy Terms & Conditions Contact Us Ethical Conduct Grievance Redressal News News Archive Topics Archive Download DevBytes Find Cricket Statistics
    Follow us on
    Facebook Twitter Linkedin
    All rights reserved © NewsBytes 2024