GoFetch security flaw is "unpatchable" on Apple M1 and M2 chips — but all is not lost

Apple M-series chip logos against a multicolored background
(Image credit: Future)

The researchers who recently uncovered the GoFetch vulnerability affecting Apple M1 and M2 chips have come forward with new information that could be both good and bad news.

GoFetch plagues Apple M-series and Intel Raptor Lake CPUs, and could result in the theft of sensitive information. It is described as a side-channel attack that leans on the performance-enhancing prediction features many modern silicons carry.

In that respect, it’s similar to previously disclosed vulnerabilities such as Spectre or Meltdown. To achieve better performance, some chips try to “predict” the software’s next moves, and load the data in the memory in advance. That way, when the data is needed, it’s already present and thus results in faster performance. But this data can be leaked, and fixing the issue might mean a decrease in performance.

Good news and bad news

The good news is that generally, this vulnerability can be easily addressed by disabling the speculative feature. 

True, it will result in poorer performance, but in the case of GoFetch, that decrease in performance would only be limited to cryptographic functions, so it shouldn’t be that big of a deal. The bad news is that this problem cannot be solved on the M1 and M2. 

"We observe that the DIT bit set on M3 CPUs effectively disables the DMP. This is not the case for the M1 and M2," the researchers explained. 

The silver lining here is that there is a workaround. As The Register explained in its writeup, Apple’s M-series chips have two types of cores: Firestorm and Icestorm. GoFetch only works on Firestorm cores, meaning that if cryptographic functions are to be moved over to Icestorm, it would solve the problem. However, Icestorm is smaller and slower than Firestorm, so the performance will still take a hit. Security won’t however, and that should be the whole point.

More from TechRadar Pro

TOPICS

Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, IoT, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations). In his career, spanning more than a decade, he’s written for numerous media outlets, including Al Jazeera Balkans. He’s also held several modules on content writing for Represent Communications.

Read more
An abstract image of a lock against a digital background, denoting cybersecurity.
Apple CPU security issue could let hackers steal user data from browsers
Security
Microsoft reveals more on a potentially major Apple macOS security flaw
Image of laptop infected with malware threat
This devious new macOS malware disguises itself as Chrome, Zoom installers
AMD logo
Security flaw means AMD Zen CPUs can be "jailbroken"
A person at a laptop with a cybersecure lock symbol floating above it.
Parallels Desktop has some worrying security flaws for Mac users
Apple's new "Share Item Location" feature for AirTags.
Apple security alert - zero-day patched, so update your devices now
Latest in Security
NHS
NHS IT supplier hit with major fine following ransomware attack
Data leak
Top home hardware firm data leak could see millions of customers affected
Representational image depecting cybersecurity protection
Third-party security issues could be the biggest threat facing your business
A stylized depiction of a padlocked WiFi symbol sitting in the centre of an interlocking vault.
Broadcom warns of worrying security flaws affecting VMware tools
Android Logo
Devious new Android malware uses a Microsoft tool to avoid being spotted
URL phishing
HaveIBeenPwned owner suffers phishing attack that stole his Mailchimp mailing list
Latest in News
Pro-Ject A1.2 in black, playing a vinyl record in a hi-fi listening room
Pro-Ject's new fully-automatic turntable could be the buy of Record Store Day 2025
Intergalactic: The Heretic Prophet
Intergalactic: The Heretic Prophet reportedly won't release until after 2026, as Neil Druckmann says that staff 'are playing it at the office' right now - but I don't think I can wait that long
Screenshot from action RPG soulslike Lies of P
Lies of P Overture won't elaborate on the game's eyebrow-raising post-credits twist, and I think that's good news
Nintendo Switch 2
The Switch 2 launching with a Mario Kart game 'is very unlike Nintendo' compared to the original Switch releasing with Breath of the Wild, says former marketing leads: 'That's what's gonna make you want to buy the new hardware'
Kindle de Amazon
The latest Kindle update finally fixes page turning – and adds the perfect reading tool for my sieve-like brain
Waze voice control
Waze is ditching Google Assistant for Gemini on iOS, and for good reasons