Branch Privilege Injection: Compromising Spectre v2 Hardware Mitigations by Exploiting Branch Predictor Race Conditions
Sandro Rüegge, Johannes Wikner, Kaveh Razavi
34th USENIX Security Symposium · Day 1
This groundbreaking paper from ETH Zurich introduces **Branch Predictor Race Conditions (BPRC)**, a novel class of microarchitectural vulnerabilities that undermine hardware-enforced mitigations against **Spectre v2** attacks on all recent Intel CPUs. The research, which earned a Distinguished Paper Award at USENIX Security, reveals that the asynchronous nature of branch predictor operations can lead to critical security boundaries being breached. Specifically, BPRC allows for the injection of privileged branch predictions from less privileged domains, effectively bypassing mechanisms like **eIBRS** (enhanced Indirect Branch Restricted Speculation) designed to prevent such cross-privilege attacks.
AI review
This is the real deal — a novel vulnerability class that breaks eIBRS across six generations of Intel silicon, with a working end-to-end exploit leaking kernel memory at 5.6 KiB/s. Distinguished Paper Award was deserved. If you work on anything touching x86 kernel security, you need to understand this.