New Specter-Based CPU vulnerability allows guests to steal sensitive data from the cloud


  • Eth Zurich scientists found a new Specter-BTI attack called VMSCAPE that lets a VM steal host data
  • It affects cloud setups using KVM/Qemu on AMD and Intel CPUs that bypass existing defense
  • They suggest rinsing the branch predictor on vmexit as a cheap solution

If Ghostbusters taught us something, it’s that spectators are notoriously difficult to get rid of.

Security researchers from the Swiss public university, ETH Zurich, recently discovered a new Specter-BTI (Branch Target injection) attack that allows a malicious virtual machine (VM) to leak sensitive data from the host system without changing host software.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top