New ARM 'TIKTAG' attack impacts Google Chrome, Linux systems
ID: e81709e6-a8f3-5ae0-964d-8486c93e2c83
STIX ID: report--e81709e6-a8f3-5ae0-964d-8486c93e2c83
Feed Name: Bleeping Computer
Threat Score
This report describes TIKTAG, a speculative-execution technique that can leak 4-bit Memory Tagging Extension (MTE) tags on ARMv8.5+ systems using two gadget types (TIKTAG-v1 and TIKTAG-v2). The researchers demonstrate high-success POCs against the Linux kernel and Chrome/V8, outline attack scenarios enabled by MTE bypass, and propose hardware and software mitigations; vendors acknowledged the issue but no widespread fixes have been deployed.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
