Page table walks conducted by the MMU during virtual to physical address translation leave a trace in the last level cache of modern AMD processors. By performing a side-channel attack on the MMU operations, it is possible to leak data and code pointers from JavaScript, breaking ASLR.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
http://www.cs.vu.nl/~herbertb/download/papers/anc_ndss17.pdf | exploit third party advisory technical description |
http://www.securityfocus.com/bid/96457 | vdb entry |
https://www.vusec.net/projects/anc | exploit third party advisory technical description |