MIT boffins’ TONTOU attack slips through Spectre defenses on Intel and AMD CPUs

← Back to the feed

MIT boffins’ TONTOU attack slips through Spectre defenses on Intel and AMD CPUs

The Register · 2 weeks ago

MIT researchers have developed TONTOU, a speculative-execution attack that can bypass some Spectre v2 defences on Intel and AMD processors. It matters because it challenges the assumption that branch-predictor state remains safe between a system’s protective sanitisation step and the later execution of sensitive code.

The technique uses carefully timed timer interrupts to re-poison branch-prediction structures after they have been neutralised, potentially steering privileged code towards data-leaking speculative paths. Tests succeeded on Intel Cascade Lake Refresh and Arrow Lake, plus AMD Zen 2 and Zen 4 systems; however, a complete exploit was demonstrated only on Zen 2, took roughly 18 minutes per attempt, and remains difficult to execute in practice.

  • Timed interrupts can undermine some Spectre v2 protections.
  • The attack affected tested Intel and AMD Linux systems.
  • Exploitation is slow and technically demanding.

Americas Business Markets World

Read the full article at the source →