Intel CPUs are still vulnerable to Spectre threats

Meltdown and Spectre
(Image credit: Shutterstock)

Intel CPUs are still vulnerable to Spectre attacks, despite both hardware and software mitigations, new research has claimed.

A team of scientists from the Vrije Universiteit Amsterdam, a public research university in The Netherlands, claim they developed a new technique that allowed them to extract sensitive information such as passwords and keys, from vulnerable Intel devices.

The technique leveraged the same methods as the infamous Spectre attack, pulling data from kernel memory and other areas of RAM which shouldn’t be accessible, all thanks to a feature that predicts what the chip should do next. The predictive feature’s goal was to make the device faster.

Open source effort

They call the new technique InSpectre Gadget. It looks for “gadgets” - code snippets, even on devices with Spectre protections set up. In a demonstration, the researchers said they worked around the FineIBT security solution and pulled data from protected kernel memory.

"We show that our tool can not only uncover new (unconventionally) exploitable gadgets in the Linux kernel, but that those gadgets are sufficient to bypass all deployed Intel mitigations," the researchers explained. 

"As a demonstration, we present the first native Spectre-v2 exploit against the Linux kernel on last-generation Intel CPUs, based on the recent BHI variant and able to leak arbitrary kernel memory at 3.5 kB/sec."

The vulnerability is tracked as CVE-2024-2201 and allegedly works against all Intel CPUs.

InSpectre Gadget is an open source tool, the researchers added. "Our efforts led to the discovery of 1,511 Spectre gadgets and 2,105 so-called 'dispatch gadgets. The latter are very useful for an attacker, as they can be used to chain gadgets and direct speculation towards a Spectre gadget."

Spectre is a critical vulnerability discovered back in 2018, together with the Meltdown flaw. It was said that a mechanism which allowed modern CPUs to work faster was leaking sensitive data. Mitigations also resulted in some devices working slower.

More from TechRadar Pro

TOPICS

Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, IoT, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations). In his career, spanning more than a decade, he’s written for numerous media outlets, including Al Jazeera Balkans. He’s also held several modules on content writing for Represent Communications.

Read more
An abstract image of a lock against a digital background, denoting cybersecurity.
Apple CPU security issue could let hackers steal user data from browsers
AMD logo
Security flaw means AMD Zen CPUs can be "jailbroken"
Security
Intel slams Nvidia and AMD, claims chip giants have huge numbers of security flaws
AMD logo
AMD patches high severity security flaw affecting Zen chips
AMD Ryzen 5 7600X processor
AMD confirms processor security flaws after Asus patch slips out early
A person at a laptop with a cybersecure lock symbol floating above it.
Parallels Desktop has some worrying security flaws for Mac users
Latest in Security
Data Breach
Thousands of healthcare records exposed online, including private patient information
China
Juniper patches security flaws which could have let hackers take over your router
Representational image depecting cybersecurity protection
GitLab has patched a host of worrying security issues
Ai tech, businessman show virtual graphic Global Internet connect Chatgpt Chat with AI, Artificial Intelligence.
AI agents can be hijacked to write and send phishing attacks
China
Volt Typhoon threat group had access to American utility networks for the best part of a year
Abstract image of cyber security in action.
MassJacker malware targets those looking for pirated software
Latest in News
Quordle on a smartphone held in a hand
Quordle hints and answers for Monday, March 17 (game #1148)
NYT Strands homescreen on a mobile phone screen, on a light blue background
NYT Strands hints and answers for Monday, March 17 (game #379)
NYT Connections homescreen on a phone, on a purple background
NYT Connections hints and answers for Monday, March 17 (game #645)
Apple iPhone 16 Pro HANDS ON
Leaked iPhone 17 dummy units may have given us our best look yet at all four models
A super close up image of the Google Gemini app in the Play Store
It's official: Google Assistant will be retired for phones this year, with Gemini taking over
Quordle on a smartphone held in a hand
Quordle hints and answers for Sunday, March 16 (game #1147)