trujillo@usenixsecurity26@USENIX

Total: 1

#1 TONTOU: On the Exploitability of Time-of-Neutralization to Time-of-Use Windows [PDF] [Copy] [Kimi] [REL]

Authors: Daniël Trujillo, Mengjia Yan

Recently deployed Spectre v2 mitigations neutralize branch predictor state when switching privilege contexts or immediately prior to indirect branch execution, either through domain isolation or sanitization. These defenses assume that subsequent branch predictor behavior remains free from attacker influence until the neutralized state is used. Unfortunately, this paper shows that this assumption does not hold on recent AMD and Intel CPUs. We find that postneutralization (Time-of-Neutralization to Time-of-Use, TONTOU) windows can be exploited by an attacker to re-poison the predictor. Specifically, within the post-neutralization window, the attacker can re-direct control-flow of the victim to a training gadget that updates the predictor. To re-direct control-flow, we introduce INTERRUPT INJECTION, a primitive that exploits post-neutralization windows by leveraging the fact that interrupts can occur at nearly any point in time. Using this primitive, we demonstrate that an attacker can trigger mispredictions during kernel execution on recent AMD and Intel CPUs. To prove its practicality, we build an end-to-end exploit using INTERRUPT INJECTION that leaks arbitrary kernel memory on AMD Zen 2 at a rate of 5.47 bytes/s, despite the latest neutralization techniques.

Subject: USENIX-Sec.2026