MIT researchers found a new Spectre attack that can slip past Intel and AMD defenses
MIT researchers have discovered TONTOU, a new Spectre-style attack that can bypass defenses on recent Intel and AMD CPUs by exploiting a tiny timing window.
Intel and AMD processors have long been vulnerable to Spectre attacks since 2018. A team of MIT researchers, Daniel Trujillo and Mengjia Yan, have discovered a new method called TONTOU that can bypass existing defenses. TONTOU exploits a brief window between when a processor's branch predictor is neutralized and when it is used again.
This gap allows the attack to inject a timing-based interrupt, poisoning the predictor and potentially leaking information. The researchers tested TONTOU on Intel Cascade Lake Refresh, Arrow Lake, AMD Zen 2, and Zen 4 processors. They were able to trigger branch mispredictions on all tested platforms. While the attack isn't a fast threat, a complete end-to-end exploit was successful on an AMD Zen 2 system, leaking sensitive data.
AMD released a patch, but Intel stated they don't plan additional mitigations. The attack highlights that even well-designed defenses can have tiny vulnerabilities, leaving the Spectre issue unresolved for many users.
Written by urgent.news from Digital Trends's reporting — not their text. Machine-written — it may contain errors, so check the original before relying on it.