Close Menu
    DevStackTipsDevStackTips
    • Home
    • News & Updates
      1. Tech & Work
      2. View All

      Sunshine And March Vibes (2025 Wallpapers Edition)

      May 16, 2025

      The Case For Minimal WordPress Setups: A Contrarian View On Theme Frameworks

      May 16, 2025

      How To Fix Largest Contentful Paint Issues With Subpart Analysis

      May 16, 2025

      How To Prevent WordPress SQL Injection Attacks

      May 16, 2025

      Microsoft has closed its “Experience Center” store in Sydney, Australia — as it ramps up a continued digital growth campaign

      May 16, 2025

      Bing Search APIs to be “decommissioned completely” as Microsoft urges developers to use its Azure agentic AI alternative

      May 16, 2025

      Microsoft might kill the Surface Laptop Studio as production is quietly halted

      May 16, 2025

      Minecraft licensing robbed us of this controversial NFL schedule release video

      May 16, 2025
    • Development
      1. Algorithms & Data Structures
      2. Artificial Intelligence
      3. Back-End Development
      4. Databases
      5. Front-End Development
      6. Libraries & Frameworks
      7. Machine Learning
      8. Security
      9. Software Engineering
      10. Tools & IDEs
      11. Web Design
      12. Web Development
      13. Web Security
      14. Programming Languages
        • PHP
        • JavaScript
      Featured

      The power of generators

      May 16, 2025
      Recent

      The power of generators

      May 16, 2025

      Simplify Factory Associations with Laravel’s UseFactory Attribute

      May 16, 2025

      This Week in Laravel: React Native, PhpStorm Junie, and more

      May 16, 2025
    • Operating Systems
      1. Windows
      2. Linux
      3. macOS
      Featured

      Microsoft has closed its “Experience Center” store in Sydney, Australia — as it ramps up a continued digital growth campaign

      May 16, 2025
      Recent

      Microsoft has closed its “Experience Center” store in Sydney, Australia — as it ramps up a continued digital growth campaign

      May 16, 2025

      Bing Search APIs to be “decommissioned completely” as Microsoft urges developers to use its Azure agentic AI alternative

      May 16, 2025

      Microsoft might kill the Surface Laptop Studio as production is quietly halted

      May 16, 2025
    • Learning Resources
      • Books
      • Cheatsheets
      • Tutorials & Guides
    Home»Development»Researchers Uncover New ‘Indirector’ CPU Vulnerability in Intel Chips

    Researchers Uncover New ‘Indirector’ CPU Vulnerability in Intel Chips

    July 2, 2024

    Security researchers have identified a novel side-channel attack that can compromise the security of modern Intel CPUs variants, including Raptor Lake and Alder Lake. The attack, dubbed Indirector, leverages weaknesses in the Indirect Branch Predictor (IBP) and the Branch Target Buffer (BTB) to bypass existing defenses and steal sensitive information from processors.

    The IBP is a critical hardware component in modern CPUs that predicts the target addresses of indirect branches. Indirect branches are control flow instructions whose target address is computed only at runtime, making them challenging to predict accurately.

    Attacks using Branch Target Injection (BTI) in their operations have been the focus of extensive research by security experts since the discovery of the Spectre and Meltdown attacks in 2018.

    Indirector CPU Vulnerability

    The Indirector attack developed by University of California San Diego researchers exploits weaknesses in Intel CPUs to launch precise Branch Target Injection (BTI) attacks. Attackers can use a custom tool called the iBranch Locator to locate any indirect branch and then perform precision-targeted IBP and BTB injections to execute speculative code. This allows attackers to steal sensitive information from the processor using a side-channel attack.

    Source: indirector.cpusec.org

    This tool enables two high-precision attacks:

    IBP Injection Attack: Locates and injects arbitrary target addresses into victim IBP entries.
    BTB Injection Attack: Injects malicious targets into the victim’s BTB entry, misleading it through BTB prediction.

    These attacks can potentially bypass existing defenses and compromise system security across various scenarios, including cross-process and cross-privilege situations. The paper has stated that while Intel has already offered several mitigations to protect the BTB and IBP from different types of target injection attacks, such as Indirect Branch Restricted Speculation (IBRS), Single Thread Indirect Branch Predictors (STIBP), and Indirect Branch Predictor Barrier, these defenses were found inadequate and did not always correspond to advertised goals.

    The researchers stated their surprise on the discovery of potential attack surfaces despite the implementation of these measures. The research paper behind the study has three main important contributions:

    The paper presents the first major analysis of the Indirect Branch Predictor and its interaction with the Branch Target Buffer in the recent Intel processor families. The paper details the size, structure, and precise indexing and tagging hash functions.
     The paper analyzes mitigation mechanisms (IBRS, STIBP, and IBPB) on Intel CPUs designed to protect against BTB and IBP target injection attacks.
    The paper demonstrated the use of the iBranch Locator as an efficient  tool with the capability of locating any indirect branches within the IBP without requiring prior data on the the branch. The paper highlights that by using this tool, attackers can successfully break address space layout randomization.

    Intel Indirector Mitigations

    For Intel processors, researchers recommend more aggressive use of the Indirect Branch Predictor Barrier (IBPB) and suggest the incorporation of more fine-grained BPU isolation across security domains in future CPU designs.

    Possible further mitigations include a more aggressive use of the Indirect Branch Predictor Barrier (IBPB) and hardening the Branch Prediction Unit (BPU) design through the incorporation of more complex tags, encryption, and randomization. The researchers disclosed their findings to Intel in February 2024, with the researchers stating that Intel had informed other affected hardware and software vendors about the vulnerability.

    The researchers’ discoveries underscore the importance of ongoing scrutiny and analysis of hardware components and the need for chip manufacturers to continually improve their designs to stay ahead of potential threats.

    The authors thanked anonymous reviewers for helpful suggestions on the research paper.

    Source: Read More

    Facebook Twitter Reddit Email Copy Link
    Previous ArticleUnderstanding Amazon Aurora MySQL storage space utilization
    Next Article EU Flexes Muscles: Meta’s ‘Pay or Consent’ Model Faces DMA Challenge

    Related Posts

    Machine Learning

    LLMs Struggle with Real Conversations: Microsoft and Salesforce Researchers Reveal a 39% Performance Drop in Multi-Turn Underspecified Tasks

    May 17, 2025
    Machine Learning

    This AI paper from DeepSeek-AI Explores How DeepSeek-V3 Delivers High-Performance Language Modeling by Minimizing Hardware Overhead and Maximizing Computational Efficiency

    May 17, 2025
    Leave A Reply Cancel Reply

    Continue Reading

    CodeSOD: intint

    News & Updates

    Steps to Build an Interactive Text-to-Image Generation Application using Gradio and Hugging Face’s Diffusers

    Machine Learning

    CVE-2025-46826 – INSA Rouen insa-auth Information Disclosure

    Common Vulnerabilities and Exposures (CVEs)

    Meta CEO Mark Zuckerberg and Spotify CEO Daniel Ek issue letter to the EU

    Artificial Intelligence

    Highlights

    Development

    Top AI Tools for Sports

    June 1, 2024

    The use of Artificial Intelligence in sports is rapidly expanding, from post-game analysis and in-game…

    The making of the Figma Pattern Library

    November 22, 2024

    Apple is building a high-security OS to run its AI data centers – here’s what we know so far

    June 18, 2024

    Best SEO Agency in India

    July 9, 2024
    © DevStackTips 2025. All rights reserved.
    • Contact
    • Privacy Policy

    Type above and press Enter to search. Press Esc to cancel.