”The GoFetch app connects to the targeted app and feeds it inputs that it signs or decrypts. As its doing this, it extracts the app secret key that it uses to perform these cryptographic operations. This mechanism means the targeted app need not perform any cryptographic operations on its own during the collection period.”

https://arstechnica.com/security/2024/03/hackers-can-extract-secret-encryption-keys-from-apples-mac-chips/

Reply to this note

Please Login to reply.

Discussion

I feel like these unpatchable vulns pop up in the news cycle every few years and then get patched and disappear. Any word from Apple?