Lune

USENIX Security2026Top-tier venue

TONTOU: On the Exploitability of Time-of-Neutralization to Time-of-Use Windows

Daniël Trujillo, Mengjia Yan

2026Year

Abstract

Recently deployed Spectre v2 mitigations neutralize branch predictor state when switching privilege contexts or immediately prior to indirect branch execution, either through domain isolation or sanitization. These defenses assume that subsequent branch predictor behavior remains free from attacker influence until the neutralized state is used.

Unfortunately, this paper shows that this assumption does not hold on recent AMD and Intel CPUs. We find that postneutralization (Time-of-Neutralization to Time-of-Use, TON-TOU) windows can be exploited by an attacker to re-poison the predictor. Specifically, within the post-neutralization window, the attacker can re-direct control-flow of the victim to a training gadget that updates the predictor.

To re-direct control-flow, we introduce INTERRUPT INJEC-TION, a primitive that exploits post-neutralization windows by leveraging the fact that interrupts can occur at nearly any point in time. Using this primitive, we demonstrate that an attacker can trigger mispredictions during kernel execution on recent AMD and Intel CPUs. To prove its practicality, we build an end-to-end exploit using INTERRUPT INJECTION that leaks arbitrary kernel memory on AMD Zen 2 at a rate of 5.47 bytes/s, despite the latest neutralization techniques.

Ask about this paper

Your agent reads all of it.

Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.

Questions to start from

Your agent calls

Luneget_paper_fulltext

Ask in Lune

Free to start. No credit card required.

lune papers fulltext bc50b754-ca91-4546-bdde-f723dcaf6f51

Builds on10

Related papers

Dusk over the sea between two cliffs drawn in fine vertical lines