FLOP: Breaking the Apple M3 CPU via False Load Output Predictions
Jason Kim, Jalen Chuang, Daniel Genkin, Yuval Yarom
摘要
To bridge the ever-increasing gap between the fast execution speed of modern processors and the long latency of memory accesses, CPU vendors continue to introduce newer and more advanced optimizations. While these optimizations improve performance, research has repeatedly demonstrated that they may also have an adverse impact on security. In this work, we identify that recent Apple M-and A-series processors implement a load value predictor (LVP), an optimization that predicts the contents of memory that the processor loads before the contents are actually available. This allows processors to alleviate slowdowns from Read-After-Write dependencies, as instructions can now be executed in parallel rather than sequentially. To evaluate the security impact of Apple's LVP implementation, we first investigate the implementation, identifying the conditions for prediction. We then show that although the LVP cannot directly predict 64-bit values (e.g., pointers), prediction of smaller-size values can be leveraged to achieve arbitrary memory access. Finally, we demonstrate end-to-end attack exploit chains that build on the LVP to obtain a 64-bit read primitive within the Safari and Chrome browsers.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了最后一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper7
- Keytar: Practical Keystroke Timing Attacks and Input ReconstructionMufan Qiu, Lihsuan Chuang, Dohhyun Kim, Huaizhi Qu 等S&P 2026 · 被引用 2 次
- dfence: Fine-Grained Speculation Barriers for Efficient and Effective Hardware-Software Protection in the Spectre EraDavide Davoli, Marton Bognar, Lesly-Ann Daniel, Benjamin Gregoire 等CCS 2026 · 被引用 1 次
- SSBench: Automated Characterization of Memory Dependence Predictors on Modern CPUsChang Liu, Yu Jin, Yuchen Fan, Tianrui Xiao 等ISCA 2026 · 被引用 1 次
- Arm Weak Memory Consistency on Apple Silicon: What Is It Good For?Yossi Khayet, Adam MorrisonASPLOS 2026
- Transient Architectural Execution: From Weird Gates to Weird ProgramsPing-Lun Wang, Fraser Brown, Riccardo Paccagnella, Eyal Ronen 等S&P 2026
它引用的顶会 Paper23
- Spectre Attacks: Exploiting Speculative ExecutionPaul Kocher, Jann Horn, Anders Fogh, Daniel Genkin 等S&P 2019 · 被引用 2,435 次
- Meltdown: Reading Kernel Memory from User SpaceMoritz Lipp, Michael Schwarz, Daniel Gruss, Thomas Prescher 等USENIX Security 2018 · 被引用 1,456 次
- Foreshadow: Extracting the Keys to the Intel SGX Kingdom with Transient Out-of-Order ExecutionJo Van Bulck, Marina Minkin, Ofir Weisse, Daniel Genkin 等USENIX Security 2018 · 被引用 1,175 次
- Fallout: Leaking Data on Meltdown-resistant CPUsClaudio Canella, Daniel Genkin, Lukas Giner, Daniel Gruss 等CCS 2019 · 被引用 289 次
- ret2spec: Speculative Execution Using Return Stack BuffersGiorgi Maisuradze, Christian RossowCCS 2018 · 被引用 282 次
相关 Paper
- SLAP: Data Speculation Attacks via Load Address Prediction on Apple SiliconJason Kim, Daniel Genkin, Yuval YaromS&P 2025
- Augury: Using Data Memory-Dependent Prefetchers to Leak Data at RestJose Rodrigo Sanchez Vicarte, Michael Flanders, Riccardo Paccagnella, Grant Garrett-Grossman 等S&P 2022 · 被引用 66 次
- New Predictor-Based Attacks in ProcessorsShuwen Deng, Jakub SzeferDAC 2021 · 被引用 7 次
- iEnFlow: Endogenous Control-Flow Attacks via Conditional Branch Prediction on Apple SiliconKaiyuan Rong, Jiajie Chen, Junqi Fang, Peng Qu 等CCS 2026
- iLeakage: Browser-based Timerless Speculative Execution Attacks on Apple DevicesJason Kim, Stephan van Schaik, Daniel Genkin, Yuval YaromCCS 2023 · 被引用 16 次
