New Spectre v2 Variant Exposes Intel, AMD, Arm CPUs to Data Leaks
Researchers from the VUSec group at Vrije Universiteit Amsterdam in the Netherlands and Scuola Superiore Sant’Anna in Italy have disclosed a new variant of the Spectre v2 attack that affects systems powered by Intel, AMD, and Arm CPUs.
The researchers named it Branch Target Reuse (BTR), and it targets the just-in-time (JIT) compilers relied upon by operating system kernels, web browsers, and runtimes.
An attacker able to run code on a targeted machine could exploit BTR to steal sensitive data from memory, such as password hashes. Attacks launched from malicious web pages also appear feasible, but the researchers have yet to build a complete browser exploit.
Spectre v2 BTR exploits how processors handle code that changes at runtime. “The key insight behind the attack is that, while modern CPUs restore architectural code coherence after self-modification, they do not necessarily invalidate stale indirect branch prediction entries (i.e., branch targets),” the...
Copyright of this story solely belongs to www.securityweek.com. To see the full text click HERE