Downfall Attacks (downfall.page)
from tedu to cloudsec on 08 Aug 2023 19:42
https://azorius.net/g/cloudsec/p/C1pr8K75BXYW1W5Msw-Downfall-Attacks

Downfall attacks targets a critical weakness found in billions of modern processors used in personal and cloud computers. This vulnerability, identified as CVE-2022-40982, enables a user to access and steal data from other users who share the same computer. For instance, a malicious app obtained from an app store could use the Downfall attack to steal sensitive information like passwords, encryption keys, and private data such as banking details, personal emails, and messages. Similarly, in cloud computing environments, a malicious customer could exploit the Downfall vulnerability to steal data and credentials from other customers who share the same cloud computer.

#cloudsec #cpu

threaded - newest

tedu on 08 Aug 2023 19:42 collapse

Everybody gets a leaky sidechannel!