USENIX Security2026Top-tier venue
TONTOU: On the Exploitability of Time-of-Neutralization to Time-of-Use Windows
Daniël Trujillo, Mengjia Yan
Abstract
Recently deployed Spectre v2 mitigations neutralize branch predictor state when switching privilege contexts or immediately prior to indirect branch execution, either through domain isolation or sanitization. These defenses assume that subsequent branch predictor behavior remains free from attacker influence until the neutralized state is used.
Unfortunately, this paper shows that this assumption does not hold on recent AMD and Intel CPUs. We find that postneutralization (Time-of-Neutralization to Time-of-Use, TON-TOU) windows can be exploited by an attacker to re-poison the predictor. Specifically, within the post-neutralization window, the attacker can re-direct control-flow of the victim to a training gadget that updates the predictor.
To re-direct control-flow, we introduce INTERRUPT INJEC-TION, a primitive that exploits post-neutralization windows by leveraging the fact that interrupts can occur at nearly any point in time. Using this primitive, we demonstrate that an attacker can trigger mispredictions during kernel execution on recent AMD and Intel CPUs. To prove its practicality, we build an end-to-end exploit using INTERRUPT INJECTION that leaks arbitrary kernel memory on AMD Zen 2 at a rate of 5.47 bytes/s, despite the latest neutralization techniques.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext bc50b754-ca91-4546-bdde-f723dcaf6f51Builds on10
- Spectre Attacks: Exploiting Speculative ExecutionPaul Kocher, Jann Horn, Anders Fogh, Daniel Genkin et al.S&P 2019 · 2,435 citations
- Nemesis: Studying Microarchitectural Timing Leaks in Rudimentary CPU Interrupt LogicJo Van Bulck, Frank Piessens, Raoul StrackxCCS 2018 · 141 citations
- InSpectre Gadget: Inspecting the Residual Attack Surface of Cross-privilege Spectre v2Sander Wiebing, Alvise de Faveri Tron, Herbert Bos, Cristiano GiuffridaUSENIX Security 2024 · 32 citations
- Phantom: Exploiting Decoder-detectable MispredictionsJohannes Wikner, Daniël Trujillo, Kaveh RazaviMICRO 2023 · 19 citations
- Indirector: High-Precision Branch Target Injection Attacks Exploiting the Indirect Branch PredictorLuyi Li, Hosein Yavarzadeh, Dean M. TullsenUSENIX Security 2024 · 18 citations
Related papers
- Branch Privilege Injection: Compromising Spectre v2 Hardware Mitigations by Exploiting Branch Predictor Race ConditionsSandro Rüegge, Johannes Wikner, Kaveh RazaviUSENIX Security 2025
- RETBLEED: Arbitrary Speculative Code Execution with Return InstructionsJohannes Wikner, Kaveh RazaviUSENIX Security 2022
- Training Solo: On the Limitations of Domain Isolation Against Spectre-v2 AttacksSander Wiebing, Cristiano GiuffridaS&P 2025
- Branch History Injection: On the Effectiveness of Hardware Mitigations Against Cross-Privilege Spectre-v2 AttacksEnrico Barberis, Pietro Frigo, Marius Muench, Herbert Bos et al.USENIX Security 2022
- Breaking the Barrier: Post-Barrier Spectre AttacksJohannes Wikner, Kaveh RazaviS&P 2025
