By Interestana AI Editorial — AI-drafted, human-overseen. How we report
MIT Researchers Uncover New Spectre Attack Targeting Intel, AMD CPUs

Researchers at the Massachusetts Institute of Technology (MIT) have identified a new class of speculative execution vulnerability, dubbed TONTOU, capable of bypassing existing security mitigations on contemporary Intel and AMD central processing units (CPUs). This discovery, detailed in a research paper, highlights a persistent challenge in securing modern processors against sophisticated side-channel attacks. TONTOU exploits a subtle timing window that arises during the execution of certain instructions, allowing attackers to infer sensitive data that should remain inaccessible.
The Spectre vulnerability, first disclosed in 2018, demonstrated how speculative execution—a performance-enhancing technique where processors predict and pre-execute instructions—could be manipulated to leak information. Subsequent research has led to numerous hardware and software defenses designed to prevent such leaks. However, TONTOU represents a novel approach that circumvents these established protections. The researchers were able to demonstrate the attack's efficacy by targeting specific microarchitectural features present in recent Intel and AMD processor designs. The attack's success hinges on precisely measuring minute variations in execution times, which can reveal patterns indicative of secret data.
According to the MIT research team, TONTOU's effectiveness stems from its ability to exploit a previously unaddressed timing side-channel. Unlike earlier Spectre variants that might rely on cache timing, TONTOU leverages differences in how the processor handles specific instruction sequences. This allows it to operate even on systems that have implemented standard Spectre and Meltdown mitigations. The implications of this finding are significant, suggesting that the ongoing arms race between attackers and defenders in the realm of speculative execution is far from over. The researchers have not yet released specific exploit code but have provided detailed technical analysis of the vulnerability's mechanics.
The discovery of TONTOU underscores the complexity of processor security and the ongoing need for vigilance and innovation in developing robust defenses. While the researchers have not publicly disclosed the full list of affected CPU models, they indicate that modern processors from both Intel and AMD are susceptible due to shared microarchitectural principles that enable speculative execution. The team plans to collaborate with CPU manufacturers to develop and deploy patches and updated security guidelines to address this new threat. The findings are expected to prompt further investigation into other potential timing-based vulnerabilities across the semiconductor industry.
Original source — read the full reporting at the publisher:
Read on Digital TrendsGet the weekly AI digest
AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.