A Comprehensive Survey of Transient Execution Vulnerabilities: from Meltdown and Specter to Modern Variants

Faisal Mushtaq (1)
(1) Department of Computer Science and Engineering, North campus University of Kashmir, India
Fulltext View | Download
How to cite (IJASCE) :
Mushtaq, F. (2026). A Comprehensive Survey of Transient Execution Vulnerabilities: from Meltdown and Specter to Modern Variants. International Journal of Advanced Science Computing and Engineering, 8(2), 71–80. https://doi.org/10.62527/ijasce.8.2.304

Meltdown and Specter exploit hardware vulnerabilities in modern processors. These vulnerabilities allow programs to steal data currently being processed on the computer. Although programs are typically not permitted to read data from other programs, a malicious program can exploit Meltdown and Specter to access secrets stored in the memory of other running programs. This analysis covers distinct attack vectors across multiple processor architectures and provides a systematic taxonomy based on exploitation mechanisms, targeted microarchitectural components, and threat models. Although implementation-specific vulnerabilities like Meltdown have been effectively mitigated, architectural issues exemplified by Specter continue to challenge the security community. This paper also includes explainable machine learning methods for detecting Meltdown and Specter.  The dataset utilized was synthetic and does not represent actual attacks. Genuine attackers may evade detection, as we did not test against real malicious activity. The detector requires further assessment on authentic systems to evaluate its operational overhead and reliability. Future research should concentrate on: (1) designing processors with speculation techniques that leave no detectable traces; (2) developing tools for the preemptive identification of vulnerabilities; (3) establishing formal methodologies to validate security guarantees; and (4) designing architectures, such as RISC-V, with integrated security features.

M. Lipp et al., "Meltdown: Reading kernel memory from user space," in Proc. 27th USENIX Conf. Security Symp. (SEC'18), Baltimore, MD, USA, Aug. 2018, pp. 973–990.

P. Kocher et al., "Spectre attacks: Exploiting speculative execution," in Proc. 2019 IEEE Symp. Security Privacy (SP), IEEE, 2019, pp. 1–19, doi:10.1109/sp.2019.00002.

Intel Corporation, "Software security guidance: Hardware behaviour related to speculative execution," Intel Developer Zone, Apr. 2026. Available: https://www.intel.com/content/www/us/en/developer/articles/ technical/software-security-guidance/technical-documentation/hardware-behaviour-related-to-speculative-execution.html.

J. Van Bulck et al., "Foreshadow: Extracting the keys to the Intel SGX kingdom with transient out-of-order execution," in Proc. 27th USENIX Conf. Security Symp. (SEC'18), Baltimore, MD, USA, Aug. 2018, pp. 991–1008.

S. van Schaik et al., "RIDL: Rogue in-flight data load," in Proc. 2019 IEEE Symp. Security Privacy (SP), IEEE, 2019, pp. 88–105, doi:10.1109/sp.2019.00087.

C. Canella et al., "Fallout," in Proc. 2019 ACM SIGSAC Conf. Comput. Commun. Security, ACM, 2019, pp. 769–784, doi:10.1145/3319535.3363219.

M. Schwarz et al., "ZombieLoad," in Proc. 2019 ACM SIGSAC Conf. Comput. Commun. Security, ACM, 2019, pp. 753–768, doi:10.1145/3319535.3354252.

D. Evtyushkin, R. Riley, N. Abu-Ghazaleh, and D. Ponomarev, "BranchScope," in Proc. 23rd Int. Conf. Architectural Support Program. Languages Operating Syst., ACM, 2018, pp. 693–707, doi:10.1145/3173162.3173204.

P. Frigo, C. Giuffrida, H. Bos, and K. Razavi, "Grand Pwning Unit: Accelerating microarchitectural attacks with the GPU," in Proc. 2018 IEEE Symp. Security Privacy (SP), IEEE, 2018, pp. 195–210, doi:10.1109/sp.2018.00022.

V. Kiriansky and C. Waldspurger, "Speculative buffer overflows: Attacks and defenses," arXiv:1807.03757, Jul. 2018, doi: 10.48550/arXiv.1807.03757. [Online]. Available: https://arxiv.org/abs/1807.03757.

J. Van Bulck et al., "LVI: Hijacking transient execution through microarchitectural load value injection," in Proc. 2020 IEEE Symp. Security Privacy (SP), IEEE, 2020, pp. 54–72, doi:10.1109/sp40000.2020.00089.

S. McFarling, "Combining branch predictors," Technical Report TN-36, Digital Western Research Laboratory, 1993.

M. D. Smith and M. Johnson, "Superscalar processor design," Synthesis Lectures on Computer Architecture, vol. 1, no. 1, pp. 1–146, 2006.

A. Moshovos, S. E. Breach, T. N. Vijaykumar, and G. S. Sohi, "Dynamic speculation and synchronization of data dependences," ACM SIGARCH Comput. Architecture News, vol. 25, no. 2, pp. 181–193, May 1997, doi:10.1145/384286.264189.

C. Percival, "Cache missing for fun and profit," in Proc. BSDCan, 2005.

B. Gras, K. Razavi, H. Bos, and C. Giuffrida, "Translation leak-aside buffer: Defeating cache side-channel protections with TLB attacks," in Proc. 27th USENIX Security Symp. (SEC'18), Baltimore, MD, USA, Aug. 2018, pp. 955–972.

G. Hinton et al., "The microarchitecture of the Pentium 4 processor," Intel Technol. J., vol. Q1, 2001.

K. J. Nesbit and J. E. Smith, "Data cache prefetching using a global history buffer," IEEE Micro, vol. 25, no. 1, pp. 90–97, Jan. 2005, doi:10.1109/mm.2005.6.

A. Randal, "Transient execution vulnerabilities in the security context of server hardware," Univ. of Cambridge Press, 2023.

D. J. Bernstein, "Cache-timing attacks on AES," Dept. of Math., Stat., and Comput. Sci., Univ. of Illinois at Chicago, Chicago, IL, USA, Tech. Rep., 2005. [Online]. Available: https://cr.yp.to/antiforgery/cachetiming-20050414.pdf.

Y. Yarom and K. Falkner, "FLUSH+RELOAD: A high resolution, low noise, L3 cache side-channel attack," in Proc. 23rd USENIX Security Symp. (SEC'14), San Diego, CA, USA, Aug. 2014, pp. 719–732.

D. A. Osvik, A. Shamir, and E. Tromer, "Cache attacks and countermeasures: The case of AES," in Lecture Notes in Computer Science, Springer, 2006, pp. 1–20, doi:10.1007/11605805_1.

D. Gruss, C. Maurice, K. Wagner, and S. Mangard, "Flush+Flush: A fast and stealthy cache attack," in Lecture Notes in Computer Science, Springer, 2016, pp. 279–299, doi:10.1007/978-3-319-40667-1_14.

F. Liu, Y. Yarom, Q. Ge, G. Heiser, and R. B. Lee, "Last-level cache side-channel attacks are practical," in Proc. 2015 IEEE Symp. Security Privacy, IEEE, 2015, pp. 605–622, doi:10.1109/sp.2015.43.

M. Schwarz, M. Schwarzl, M. Lipp, J. Masters, and D. Gruss, "NetSpectre: Read arbitrary memory over network," in Lecture Notes in Computer Science, Springer, 2019, pp. 279–299, doi:10.1007/978-3-030-29959-0_14.

A. Bhattacharyya et al., "SMoTherSpectre," in Proc. 2019 ACM SIGSAC Conf. Comput. Commun. Security, ACM, 2019, pp. 785–800, doi:10.1145/3319535.3363194.

G. Irazoqui, T. Eisenbarth, and B. Sunar, "S$A: A shared cache attack that works across cores and defies VM sandboxing—and its application to AES," in Proc. 2015 IEEE Symp. Security Privacy, IEEE, 2015, pp. 591–604, doi:10.1109/sp.2015.42.

Y. Kim et al., "Flipping bits in memory without accessing them," ACM SIGARCH Comput. Architecture News, vol. 42, no. 3, pp. 361–372, Jun. 2014, doi:10.1145/2678373.2665726.

J. Stecklina and T. Prescher, "LazyFP: Leaking FPU register state using microarchitectural side-channels," arXiv:1806.07480, Jun. 2018. [Online]. Available: https://arxiv.org/abs/1806.07480.

E. M. Koruyeh, K. N. Khasawneh, C. Song, and N. Abu-Ghazaleh, "Spectre returns! Speculation attacks using the return stack buffer," IEEE Design Test, vol. 41, no. 2, pp. 47–55, Apr. 2024, doi:10.1109/mdat.2024.3352537.

G. Maisuradze and C. Rossow, "ret2spec," in Proc. 2018 ACM SIGSAC Conf. Comput. Commun. Security, ACM, 2018, pp. 2109–2122, doi:10.1145/3243734.3243761.

S. van Schaik, M. Minkin, A. Kwong, D. Genkin, and Y. Yarom, "CacheOut: Leaking data on Intel CPUs via cache evictions," in Proc. 2021 IEEE Symp. Security Privacy (SP), IEEE, 2021, pp. 339–354, doi:10.1109/sp40001.2021.00064.

J. Horn, "Speculative execution, variant 4: Speculative store bypass," Google Project Zero Blog, May 2018.

J. Fustos, M. Bechtel, and H. Yun, "SpectreRewind," in Proc. 4th ACM Workshop Attacks Solutions Hardware Security, ACM, 2020, pp. 117–126, doi:10.1145/3411504.3421216.

AMD, "Software techniques for managing speculation on AMD processors," White Paper, 2018.

O. Weisse et al., "Foreshadow-NG: Breaking the virtual memory abstraction with transient out-of-order execution," Technical report, 2018. [Online]. Available: https://foreshadowattack.eu/foreshadow-NG.pdf.

Amazon Web Services, "Processor speculative execution research disclosure," AWS Security Bulletin, Jan. 2018.

C. Canella et al., "A systematic evaluation of transient execution attacks and defences," in Proc. 28th USENIX Security Symp. (SEC'19), Santa Clara, CA, USA, Aug. 2019, pp. 249–266.

ARM, "Cache speculation side-channels," White Paper, Jan. 2018.

Z. Pan and P. Mishra, "Automated detection of Spectre and Meltdown attacks using explainable machine learning," in Proc. 2021 IEEE Int. Symp. Hardware Oriented Security Trust (HOST), IEEE, 2021, pp. 24–34, doi:10.1109/host49136.2021.9702278.

B. Ahmad, "Real time detection of Spectre and Meltdown attacks using machine learning," CoRR, vol. abs/2006.01442, 2020.

C. Li and J.-L. Gaudiot, "Online detection of Spectre attacks using microarchitectural traces from performance counters," in Proc. 2018 30th Int. Symp. Comput. Architecture High Perform. Comput. (SBAC-PAD), IEEE, 2018, pp. 25–28, doi:10.1109/cahpc.2018.8645918.

H. Ragab, E. Barberis, H. Bos, and C. Giuffrida, "GhostRace: Exploiting and mitigating speculative race conditions," in Proc. 33rd USENIX Security Symp. (SEC'24), Philadelphia, PA, USA, Aug. 2024, pp. 1234–1251.

P. Turner, "Retpoline: A software construct for preventing branch-target-injection," Google Support Document, 2018.

M. Yan et al., "InvisiSpec: Making speculative execution invisible in the cache hierarchy," in Proc. 2018 51st Annu. IEEE/ACM Int. Symp. Microarchitecture (MICRO), IEEE, 2018, pp. 428–441, doi:10.1109/micro.2018.00042.

K. N. Khasawneh et al., "SafeSpec," in Proc. 56th Annu. Design Autom. Conf. 2019, ACM, 2019, pp. 1–6, doi:10.1145/3316781.3317903.

V. Kiriansky, I. Lebedev, S. Amarasinghe, S. Devadas, and J. Emer, "DAWG: A defense against cache timing attacks in speculative execution processors," in Proc. 2018 51st Annu. IEEE/ACM Int. Symp. Microarchitecture (MICRO), IEEE, 2018, pp. 974–987, doi:10.1109/micro.2018.00083.

G. Chen, S. Chen, Y. Xiao, Y. Zhang, Z. Lin, and T. H. Lai, "SgxPectre: Stealing Intel secrets from SGX enclaves via speculative execution," in Proc. 2019 IEEE Eur. Symp. Security Privacy (EuroS&P), IEEE, 2019, pp. 142–157, doi:10.1109/eurosp.2019.00020.

K. Asanović and D. A. Patterson, "Instruction sets should be free: The case for RISC-V," EECS Dept., Univ. of California, Berkeley, Berkeley, CA, USA, Tech. Rep. UCB/EECS-2014-146, Aug. 2014. [Online]. Available: http://www2.eecs.berkeley.edu/Pubs/TechRpts/2014/Archive/EECS-2014-146.pdf.