Vulnerability with Apple M-series silicon could allow attackers to steal crypto keys
Recently a hardware vulnerability with Apple M1, M2, and M3 processors was made public. There is a flaw in the silicon that allows malicious applications (no root access required) to steal crypto keys. In theory even javascript on a website could do the attack. Servers using this silicon are also vulnerable.
There is no solution from Apple to fix this, any fix requires software developers to update their applications. Updated apps can mitigate the issue on M3 processors. I'm not sure about M1 and M2.
Here's a detailed article on the topic:
https://www.zetter-zeroday.com/apple-chips/
Since we have a variety of wallets and nodes where keeping the keys safe is critical, I think this is an area that we should try to get fixed as much as possible.
If everyone could help spread the word on this, that would be highly appreciated. The linked article has information on mitigating this issue.
[link] [comments]