logo

MTE As Implemented, Part 2: Mitigation Case Studies

ID: f11585c3-08e8-5207-b503-246ca5168ef7

STIX ID: report--f11585c3-08e8-5207-b503-246ca5168ef7

Feed Name: Google Project Zero

Date Published: 2023-08-02

Date Updated: 2026-04-27

Author: Google Project Zero

...
...

This analysis evaluates how attackers can bypass ARM Memory Tagging Extensions (MTE) through known-tag (e.g., Spectre-based side channels) and unknown-tag techniques, contrasting async-MTE (architecturally observable invalid accesses and soft time windows) with sync-MTE (fault-on-retire blocking most unknown-tag paths), and mapping the resulting attacker difficulty across Chrome renderer exploitation, Chrome IPC sandbox escapes, Android Binder services, and remote messaging apps; it concludes that while async-MTE can be a meaningful soft mitigation, achieving a hard deterministic mitigation likely requires sync-MTE or combinations like Scan+MTE, with generic bypasses more feasible in renderer contexts and far rarer or bespoke in IPC/Binder/one-shot remote scenarios.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.