↓ Skip to main content
  1. posts/

Understanding Spectre: A Explainer on the Speculative Execution Vulnerability

··

Ben Visness, How does Spectre work?

Spectre is a class of vulnerabilities that exploit speculative execution, a CPU feature that makes programs faster. Ben Visness explains how it works and how to mitigate it.

Speculative execution
#

The CPU guesses whether a condition will be true and carries on. A right guess saves time. A wrong guess costs little. Out-of-order execution is related: the CPU runs instructions in a different order than written, because a memory access is much slower than a comparison or arithmetic.

Where it goes wrong
#

The CPU rolls back a wrong guess, but not completely. The cache keeps the effects. Spectre reads secret data from them.

Example
#

if (x < array1_size) {
	y = array2[array1[x] * 4096];
}

This looks harmless. A speculative load is a real load: it fetches main memory into the cache even if the CPU later discards the result. An attacker times how fast different memory locations load and reads the secret from the differences.

A practical exploit
#

The article then shows a more practical case with arrays. An out-of-bounds access under speculation loads secret data into the cache, and the attacker extracts its value. The technique works across languages and platforms, including web browsers.

Related