HomeSecurityNew Intel CPU Flaws Leak Sensitive Data

New Intel CPU bugs leak sensitive data

A new bug called “Branch Privilege Injection” that affects all modern Intel CPUs allows attackers to leak sensitive data from memory areas allocated to privileged software, such as the operating system kernel.

See also: Intel: Is it preparing to lay off thousands of employees?

Intel CPU errors

These areas typically include information such as passwords, cryptographic keys, memory from other processes, and kernel data structures, so protecting them from leaks is critical.

According to ETH Zurich researchers Sandro Rüegge , Johannes Wikner , and Kaveh Razavi , the mitigation mechanisms for the Spectre v2 vulnerability have remained effective for six years, but their new attack, dubbed “Branch Predictor Race Conditions,” can successfully bypass them. The CPU flaw, which has been documented as CVE-2024-45332 , is a race condition in the branch predictor subsystem used by Intel processors

Branch predictors, such as the Branch Target Buffer (BTB) and Indirect Branch Predictor (IBP), are specialized hardware components that attempt to predict the outcome of a branch instruction before it is executed, in order to keep the CPU's instruction pipeline full for optimal performance. These predictions are speculative, meaning that if they are wrong, they are discarded. However, when they are correct, they contribute significantly to improving performance.

Researchers found that Intel's branch predictor updates are not synchronized with instruction execution, which allows these updates to cross privilege boundaries.

See also: Intel: Pat Gelsinger is no longer the company's CEO

When a privilege level change occurs—for example, from user mode to kernel mode—there is a small window of timeduring which the update can be associated with the wrong privilege level.

Intel
New Intel CPU bugs leak sensitive data

As a consequence, isolation between user and kernel is violated, and an unprivileged user can gain access and leak data from privileged processes.

The ETH Zurich team developed an attack mechanism that trains the CPU to predict a specific branch target, and then makes a system call to transfer execution to the operating system kernel. This leads to speculative execution using a target controlled by the attacker.

This code has access to sensitive data that has been loaded into the cache, and through a side-channel attack, the data is leaked to the attacker.

The researchers demonstrated the effectiveness of the attack on a system running Ubuntu 24.04, even with the default mitigations enabled, by managing to read the contents of the file, which contains the hashed passwords of the accounts. The exploit can achieve maximum leak rates of 5.6 KB per second with 99.8% accuracy.

See also: Microsoft introduced the Surface Laptop 7 with an Intel chip

Based on the above, it becomes clear that the Branch Privilege Injection vulnerability is a new form of microarchitectural attack , similar to the well-known Spectre and Meltdown attacks , which exploit the way modern processors optimize performance through speculative execution.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

Source: bleepingcomputer

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS