Researchers Find a New ‘Indirector’ Attack Vulnerability in Intel Processors

Published:

spot_img

New Side-Channel Attack Identified in Modern Intel CPUs: The Indirector Vulnerability

Security researchers have uncovered a new and concerning vulnerability in modern Intel CPUs, including the latest variants like Raptor Lake and Alder Lake. The attack, named Indirector, exploits weaknesses in the Indirect Branch Predictor (IBP) and the Branch Target Buffer (BTB) to bypass security defenses and access sensitive data stored in processors.

The IBP is a crucial component in modern CPUs that predicts the target addresses of indirect branches, which are control flow instructions computed at runtime, making them difficult to predict accurately. The Indirector attack, developed by researchers at the University of California San Diego, utilizes precise Branch Target Injection (BTI) techniques to execute speculative code and steal information from the processor using a side-channel attack.

This attack leverages a custom tool called the iBranch Locator to identify indirect branches and inject malicious targets into the IBP and BTB entries. By using high-precision IBP and BTB injections, attackers can bypass existing defenses and compromise system security in various scenarios.

While Intel has implemented mitigations like Indirect Branch Restricted Speculation (IBRS) and Single Thread Indirect Branch Predictors (STIBP) to protect against target injection attacks, the researchers found these defenses to be inadequate. They recommend more aggressive use of the Indirect Branch Predictor Barrier (IBPB) and propose incorporating finer-grained Branch Prediction Unit (BPU) isolation in future CPU designs.

The researchers shared their findings with Intel in February 2024, prompting the company to notify other affected hardware and software vendors about the vulnerability. This discovery underscores the importance of ongoing scrutiny and improvement of hardware components to stay ahead of potential threats in the ever-evolving landscape of cybersecurity.

spot_img

Related articles

Recent articles

Walmart Shoppers Beware: Major Scam Hits Millions

A large-scale robocall scam is targeting millions of Walmart shoppers in the U.S. by impersonating the retailer’s customer service and inventing fake high-value purchases...

GCCA Celebrates Supreme Council’s Decision to Create GCC Civil Aviation Authority

GCC Civil Aviation Authority: A New Era for Gulf Air Travel A Significant Development for the Gulf Region The General Civil Aviation Authority (GCAA) of the...

Researchers Find Over 30 Vulnerabilities in AI Coding Tools That Risk Data Theft and RCE Attacks

Unveiling the IDEsaster: Security Flaws in AI-Powered Coding Environments Overview of Recent Vulnerabilities A recent investigation has uncovered over 30 security vulnerabilities lurking within popular AI-powered...

XIXILI Transforms Plus-Size Lingerie in Malaysia

## A New Era for Plus Size Lingerie: Introducing XIXILI’s Collection ### Redefining Lingerie Shopping KUALA LUMPUR, MALAYSIA - In a bold move that reshapes the...