Apple has released the post-quantum cryptography components of its corecrypto library as open source, publishing implementations of the NIST-standardized ML-KEM and ML-DSA algorithms alongside mathematical proofs, documentation, and verification tooling for independent review. The company said corecrypto underpins encryption, hashing, random number generation, and digital signatures across more than 2.5 billion active devices, and that post-quantum protections introduced in 2024 are already used in iMessage, VPN services, and TLS networking, including the PQ3 messaging protocol Apple previously described as a large-scale quantum-secure design.
Apple said it validated the code through a hybrid assurance model combining conventional testing, simulation, independent review, and formal verification, using a workflow that linked portable C implementations to Cryptol and Isabelle proofs with support from Galois. According to Apple, that process uncovered a subtle early ML-DSA flaw that could rarely produce incorrect output and likely would have escaped standard testing; the issue was fixed before deployment. The release is intended to make Apple’s analysis reproducible and give outside experts a chance to scrutinize security-critical cryptographic code as organizations prepare for future quantum threats.

Track how attackers are adapting to this technology.
3 events from the most recent confirmed update back to the earliest known activity.
Apple publicly released its post-quantum cryptography implementations in corecrypto, including ML-KEM and ML-DSA code, mathematical proofs, verification tools, and documentation for independent review. Apple said the verification effort uncovered an early ML-DSA flaw that was fixed before deployment.
Apple published a technical blueprint describing its formal verification approach for corecrypto, including methods used to validate post-quantum implementations. The work described collaboration and tooling used to prove correctness properties of cryptographic code.
Apple announced PQ3, a new post-quantum cryptographic protocol for iMessage intended to improve protection against future quantum-capable adversaries. The announcement positioned PQ3 as a large-scale quantum-secure messaging advancement for Apple's messaging platform.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Follow how adversaries are adapting to this technology, and where it touches your stack today.
6 references tracked. Mallory keeps watching after this page renders.
scworld.com
Open sourcehelpnetsecurity.com
Open sourcecyberscoop.com
Open sourcesecurity.apple.com
Open sourcetidbits.com
Open sourcesecurity.apple.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.