Conjuring: Leaking Control Flow via Speculative Fetch Attacks
Ali Hajiabadi, Trevor E. Carlson · 2024
In this work, we propose a new attack called Conjuring that exploits one of the main features of CPUs' frontend: speculative fetch of instructions. We show that the Pattern History Table (PHT) in modern CPUs are a great channel to learn and leak control flow of victim applications. Unlike prior work, Conjuring does not require that one primes the PHT or interferes with the victim execution enabling a realistic and unprivileged attacker to leak control flow information. By improving the branch predictors, our attack becomes even more serious and practical. We demonstrate the feasibility of our attack on different existing Intel, AMD, and Apple CPUs.