Ben Visness, How does Spectre work?
Spectre is a class of vulnerabilities that exploit speculative execution, a CPU feature that makes programs faster. Ben Visness explains how it works and how to mitigate it.
Speculative execution#
The CPU guesses whether a condition will be true and carries on. A right guess saves time. A wrong guess costs little. Out-of-order execution is related: the CPU runs instructions in a different order than written, because a memory access is much slower than a comparison or arithmetic.
Where it goes wrong#
The CPU rolls back a wrong guess, but not completely. The cache keeps the effects. Spectre reads secret data from them.
Example#
if (x < array1_size) {
y = array2[array1[x] * 4096];
}
This looks harmless. A speculative load is a real load: it fetches main memory into the cache even if the CPU later discards the result. An attacker times how fast different memory locations load and reads the secret from the differences.
A practical exploit#
The article then shows a more practical case with arrays. An out-of-bounds access under speculation loads secret data into the cache, and the attacker extracts its value. The technique works across languages and platforms, including web browsers.