A newly discovered vulnerability in Apple's M-series chips could expose wallet keys, academic researchers revealed in a paper published Thursday.
The vulnerability is a side channel that allows end-to-end key extraction when an Apple chip runs a cryptographic wallet, but the vulnerability cannot be directly patched because it stems from the microarchitectural design of the chip itself. Instead, this can only be mitigated by building defenses into third-party encryption software, which significantly degrades the performance of the M Series when performing cryptographic operations, especially on earlier M1 and M2 generations. The vulnerability is exploited when the target cryptographic operation and a malicious application with normal user system privileges are run on the same CPU cluster. (Ars Technica)