New issue
Advanced search Search tips

Issue 859832 link

Starred by 1 user

Issue metadata

Status: Duplicate
Merged: issue 847484
Owner: ----
Closed: Jul 3
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: Linux , Android , Windows , Chrome , Mac , Fuchsia
Pri: 2
Type: Bug-Security



Sign in to add a comment

Spectre V1 Proof of Concept works in Chrome

Reported by therealm...@gmail.com, Jul 3

Issue description

UserAgent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_13_5) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/68.0.3440.42 Safari/537.36

Steps to reproduce the problem:
1. open and download https://github.com/alephsecurity/spectreBrowserResearch
2. open console, open Spectre.html and click button
3. wait to see original value and restored value in the console

What is the expected behavior?
original value and restored value should not match.
Firefox (current stable) is not affected where as Safari also seems to be affected.

What went wrong?
original value and restored value should not match.

Background information is in the research blog:
https://alephsecurity.com/2018/06/26/spectre-browser-query-cache/

Did this work before? N/A 

Chrome version: 68.0.3440.42  Channel: beta
OS Version: OS X 10.13.5
Flash Version: 

Strict site isolation has no effect here.
 
Cc: palmer@chromium.org danno@chromium.org
Thanks for the report.

I don't *think* there is anything for us to do with this -- from our point of view the v8 mitigations for Spectre are known to have limited effectiveness. We have moved to Site Isolation as our primary mitigation, the goal of which is to prevent there being any sensitive data available in-process such that it would be vulnerable to Spectre attacks.

palmer@, danno@: Do you have thoughts on whether there is anything in this research that is new and/or actionable?
Components: Internals Internals>Sandbox>SiteIsolation
Labels: -Restrict-View-SecurityTeam allpublic OS-Android OS-Chrome OS-Fuchsia OS-Linux OS-Windows
Mergedinto: 847484
Status: Duplicate (was: Unconfirmed)
Alpeh already reported their research to us; see  Issue 847484 .
Err, Aleph, obviously.

Sign in to add a comment