



























Andreas Lindner, Uppsala University
Roberto Guanciale, Royal Institute of Technology (KTH)
Hamed Nemati, Royal Institute of Technology (KTH)
Transient execution attacks that disclose arbitrary memory commonly assume a multi-stage read-then-transmit gadget: a transient load to fetch secret data and a subsequent operation to leak that data into an observable side channel. We show that this assumption does not hold under electromagnetic (EM) observations, by verifying that a single transient load already produces value-dependent EM leakage without any explicit follow-up transmission instruction or relying on prefetching. Our results expand the set of exploitable gadgets and show that even simple processors like the Cortex-A53 are vulnerable.
BibTeX
@misc{cryptoeprint:2026/806,
author = {Can Aknesil and Andreas Lindner and Roberto Guanciale and Hamed Nemati},
title = {Spectre Without Dependent Load},
howpublished = {Cryptology {ePrint} Archive, Paper 2026/806},
year = {2026},
url = {https://eprint.iacr.org/2026/806}
}
此内容由惯性聚合(RSS阅读器)自动聚合整理,仅供阅读参考。 原文来自 — 版权归原作者所有。