iEnFlow: Endogenous Control-Flow Attacks via Conditional Branch Prediction on Apple Silicon
Kaiyuan Rong, Jiajie Chen, Junqi Fang, Peng Qu, Hanyin Liu, Youhui Zhang, Dapeng Ju, Dongsheng Wang
Abstract
Control-flow attacks have drawn increasing attention in microarchitectural security research due to their ability to expose sensitive data by revealing or manipulating program control-flow. Prior work has primarily focused on x86 architectures, with relatively few studies exploring such attacks on ARM-based Apple silicon processors. Meanwhile, existing microarchitectural side-channels that leak control-flow information on Apple silicon either rely on microarchitectural components beyond the branch predictor or lack a detailed understanding of branch predictor designs, which limits their generality and scalability.
In this paper, we present iEnFlow, the first endogenous and finegrained control-flow attacks on Apple silicon that directly exploit control-flow information originating from the branch predictor itself. We target the conditional branch predictor (CBP) and reverseengineer its internal design, including branch history length, hashing function, and predictor-table indexing scheme. Based on these reverse-engineering results, we develop primitives to read and write branch history and predictor-table entries, enabling unprivileged leakage and manipulation of the CBP on macOS. Using these primitives, we implement two attacks to demonstrate the effectiveness of
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 8136475d-9abe-419b-8783-2c8f4461b5faBuilds on39
- Spectre Attacks: Exploiting Speculative ExecutionPaul Kocher, Jann Horn, Anders Fogh, Daniel Genkin et al.S&P 2019 · 2,435 citations
- Translation Leak-aside Buffer: Defeating Cache Side-channel Protections with TLB AttacksBen Gras, Kaveh Razavi, Herbert Bos, Cristiano GiuffridaUSENIX Security 2018 · 357 citations
- KEPLER: Facilitating Control-flow Hijacking Primitive Evaluation for Linux Kernel VulnerabilitiesWei Wu, Yueqi Chen, Xinyu Xing, Wei ZouUSENIX Security 2019 · 75 citations
- Prime+Probe 1, JavaScript 0: Overcoming Browser-based Side-Channel DefensesAnatoly Shusterman, Ayush Agarwal, Sioli O'Connell, Daniel Genkin et al.USENIX Security 2021 · 73 citations
- PACMAN: attacking ARM pointer authentication with speculative executionJoseph Ravichandran, Weon Taek Na, Jay Lang, Mengjia YanISCA 2022 · 68 citations
Related papers
- SLAP: Data Speculation Attacks via Load Address Prediction on Apple SiliconJason Kim, Daniel Genkin, Yuval YaromS&P 2025
- Pathfinder: High-Resolution Control-Flow Attacks Exploiting the Conditional Branch PredictorHosein Yavarzadeh, Archit Agarwal, Max Christman, Christina Garman et al.ASPLOS 2024 · 21 citations
- SysBumps: Exploiting Speculative Execution in System Calls for Breaking KASLR in macOS for Apple SiliconHyerean Jang, Taehun Kim, Youngjoo ShinCCS 2024 · 6 citations
- Augury: Using Data Memory-Dependent Prefetchers to Leak Data at RestJose Rodrigo Sanchez Vicarte, Michael Flanders, Riccardo Paccagnella, Grant Garrett-Grossman et al.S&P 2022 · 66 citations
- Conjuring: Leaking Control Flow via Speculative Fetch AttacksAli Hajiabadi, Trevor E. CarlsonDAC 2024 · 5 citations
