CVE-2024-10929: Staying alert! Spectre-BSE exploits affects ARM® Cortex®-A72 (revisions prior to r1p0), Cortex-A73 and Cortex-A75. (15-04-2025)

Preface: The Cortex-A75 is still being used by manufacturers today. For instance, UNISOC and MediaTek continue to incorporate Cortex-A75 cores in their chipsets.

These processors are found in various mid-range and entry-level devices, providing a balance of performance and efficiency.

Background: Branch Status Eviction (BSE) is a vulnerability related to the Spectre class of security issues. It exploits a microarchitectural mechanism that allows an attacker to gain a weak form of control over the victim’s branch history, despite existing protections. This can lead to the manipulation of indirect branches and potentially result in data exfiltration.

Vulnerability details: According to the ARM® security team, Spectre-BSE exploits a micro-architectural mechanism that equips an adversary with a weak form of control over the victim’s branch history despite existing protections.

This can lead to exploitative control of indirect branches and potentially to data exfiltration. This issue affects ARM Cortex®-A72 (revisions prior to r1p0), Cortex-A73 and Cortex-A75.

Official announcement: Please see the link for details – https://www.amd.com/en/resources/product-security/bulletin/amd-sb-8007.html

Leave a Reply

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.