ZeroSecurity - Information Security News
  • Home
  • Security
    • Exploits
    • Mobile Security
  • Malware
  • Breaches
  • Crypto
  • Privacy
  • Tech
    • AI
    • Downloads
      • Malwarebytes
      • Exploits
      • Paper Downloads
    • Reviews
No Result
View All Result
SUBSCRIBE
ZeroSecurity - Information Security News
  • Home
  • Security
    • Exploits
    • Mobile Security
  • Malware
  • Breaches
  • Crypto
  • Privacy
  • Tech
    • AI
    • Downloads
      • Malwarebytes
      • Exploits
      • Paper Downloads
    • Reviews
No Result
View All Result
ZeroSecurity - Information Security News
No Result
View All Result
Home Exploits

GoFetch Exploit Impacting Both Apple M-series and Intel Raptor Lake CPUs

Kyle by Kyle
March 25, 2024
in Exploits
Reading Time: 2 mins read
Explore the GoFetch vulnerability impacting Apple M-series and Intel Raptor Lake CPUs. Uncover the exploit’s workings, implications, and potential workarounds.
Share on FacebookShare on Twitter

Recent developments have shed light on the GoFetch vulnerability, a security exploit that affects both Apple M-series and Intel Raptor Lake CPUs. This exploit leverages data memory-dependent prefetchers (DMPs), a feature similar to speculative execution vulnerabilities like Spectre, to potentially leak sensitive data.

You might also like

Hackers Exploit Maximum-Severity Cisco Zero-Day Bug Since 2023 (CVE-2026-20127)

DoubleClickjacking – The Stealthy New Web Exploit Threatening User Security

Critical Vulnerabilities Exposed in Ruijie Networks Cloud Platform

Understanding the GoFetch Exploit

GoFetch operates by exploiting DMPs, which are present in all Apple M-series CPUs and Intel’s Raptor Lake processors. When DMP is enabled, data can be siphoned off a core’s cache, thereby providing a potential entry point for cyber attackers.

Researchers have demonstrated the exploit on a dedicated website for GoFetch, showing how within a matter of minutes, 560 bits of data were leaked from an RSA-protected server.

Comparing GoFetch to Other Known Vulnerabilities

While GoFetch may not be groundbreaking, it shares similarities with other known vulnerabilities such as Spectre and Meltdown. These exploits also take advantage of a CPU’s performance-enhancing prediction features. Typically, software-based patches are used to address hardware-level exploits, often by disabling the speculative feature, which in turn reduces performance. However, this solution is not viable for M1 and M2 CPUs.

FAQ: Can DMP be disabled?

Yes, but only on certain processors. Researchers have found that setting the DIT bit on M3 CPUs effectively disables the DMP. Unfortunately, this is not the case for the M1 and M2 CPUs. Therefore, while a software patch can resolve GoFetch for M3 and Raptor Lake CPUs, it cannot be used for M1 and M2 chips as DMP will run regardless.

The Implications of the GoFetch Exploit

It’s always a concern when a performance-enhancing feature needs to be disabled due to potential data leaks. The situation is even more dire when the feature cannot be disabled at all. One proposed workaround is to blind the DMP to sensitive data whenever it’s being stored or loaded from memory. However, this solution would necessitate extensive code rewrites and could result in performance penalties.

A Potential Workaround

Interestingly, there is a workaround that doesn’t require any code rewrites. Like many modern CPUs, Apple’s M-series has two types of cores: the larger Firestorm cores and the smaller Icestorm cores. The DMP-based GoFetch exploit only works on Firestorm cores, including for M1 and M2 CPUs. Therefore, the researchers suggest running all cryptographic work solely on the Icestorm cores for now. While this may result in slower performance, it should ensure security.

Even this approach may not be foolproof. If Apple releases a future M processor with DMP enabled in its efficiency cores, there would be no safe place to run code without potentially exposing sensitive data. Given that DMP is not entirely secure, it is hoped that Apple will either fix it, remove it, or find an alternative feature before making its next-generation CPUs even more vulnerable.

Tags: apple
Previous Post

Unveiling ‘Unsaflok’: Innovative Hacking Technique Exposes Vulnerabilities in Global Hotel Security Systems

Next Post

Hackers Offered 10% of Funds Recovered After $16M Curio Smart Contract Exploit

Kyle

Kyle

Writer, and editor at ZeroSecurity. Interested in Information Security, the Blockchain, and an overall tech enthusiast. "Formal education will make you a living; self-education will make you a fortune." Contact me here: [email protected]

Recommended For You

Photo of the CISCO logo and text saying "You have been hacked!"

Hackers Exploit Maximum-Severity Cisco Zero-Day Bug Since 2023 (CVE-2026-20127)

March 6, 2026
What is DoubleClickJacking?

DoubleClickjacking – The Stealthy New Web Exploit Threatening User Security

January 1, 2025

Critical Vulnerabilities Exposed in Ruijie Networks Cloud Platform

December 25, 2024

Vulnerability (CVE-2024-54143 ) Discovered in OpenWrt’s Firmware Upgrade System

December 13, 2024

Cybercriminals Unleash Advanced Phishing-as-a-Service Toolkit Targeting Microsoft 365 Users

November 29, 2024

Major Security Vulnerability Uncovered in qBittorrent Client

November 1, 2024

Related News

Malicious Chrome Extensions Steal AI Data and Hijack Revenue in DarkSpectre Campaign

Malicious Chrome Extensions Steal AI Data and Hijack Revenue in DarkSpectre Campaign

January 30, 2026
KPMG Netherlands Listed as Victim by Nova Ransomware Group

KPMG Netherlands Listed as Victim by Nova Ransomware Group

January 24, 2026
RansomHouse Claims Breach of Key Apple Assembler Luxshare

RansomHouse Claims Breach of Key Apple Assembler Luxshare

January 20, 2026
ZeroSecurity - Information Security News

We cover the latest in technology news, Crypto, Artificial Intelligence, and the threat trends impacting these sectors.

Categories

Piracy

Tutorials

Programming

Malware Analysis

Downloads

  • Contact us
  • Press
  • Writers
  • Privacy Policy
  • Terms of Service

© 2026 ZeroSecurity, All Rights Reserved.

No Result
View All Result
  • Home
  • Security
    • Tools
  • Exploits
  • Data Breaches
  • Malware
  • Privacy
  • Mobile Security
  • Contact Us
    • Press
  • Privacy Policy

© 2026 ZeroSecurity, All Rights Reserved.

This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.