Modern Intel CPUs, including chips from the Raptor Lake and Alder Lake, are susceptible to a new type of high-precision Branch Target Injection (BTI) called "Indirector," which could be used to steal sensitive information from the CPU.
See also: Ryzen 9 9950X: AMD's first Zen 5 CPU is a "monster"

Indirector exploits flaws in the Indirect Branch Predictor (IBP) and Branch Target Buffer (BTB), two hardware components found in modern Intel, to handle speculative execution for data extraction.
Three researchers at the University of California, San Diego discovered and demonstrated the Indirector attack, with full details to be presented at the upcoming USENIX in August 2024.
What are Indirector attacks?
The Indirect Branch Predictor is designed to predict the target addresses of indirect branches using execution information, while the Branch Target Buffer predicts the target addresses of direct branches using a set-associative cache structure.
The researchers found that the two systems have flaws in their indexing, tagging, and input sharing mechanisms, and generally rely on a predictable structure that allows for highly precise targeted manipulations.
See also: CPU Removal: What It Is and Why You Should Do It
Based on the above, Indirector performs attacks that affect modern Intel, mainly using three mechanisms:

iBranch Locator: A custom tool that uses eviction-based techniques to identify victim branch pointers and labels and accurately identify IBP entries for specific branches.
IBP/BTB injections: Performs targeted injections into prediction structures for speculative code execution.
ASLR bypass: Breaks Address Space Layout Randomization (ASLR) by identifying the exact locations of indirect branches and their targets, making it easier to predict and manipulate the control flow of protected processes.
Along with the speculative execution achieved with targeted injections, the attacker can use cache side-channel techniques, such as measuring access times, to infer access data.
More details about Indirector affecting modern Intel, attack methodologies, potential data leakage mechanisms, and suggested mitigations can be found in this white paper.
See also: Boost your PC with the AMD Ryzen 5 5500 CPU
A side-channel attack represents a method used to extract data from a system based on information obtained from the physical implementation of the system, rather than exploiting a software flaw or vulnerability. These attacks can target various types of side channels, such as timing information, power consumption, electromagnetic leakage, or even audio. By carefully analyzing these unintended emissions, attackers can infer sensitive information, such as cryptographic keys or passwords, without having direct access to the protected data. As the sophistication of these attacks evolves, they pose a significant challenge to cybersecurity , requiring continued advances in defensive technologies and methodologies.
Source: bleepingcomputer
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
