Rowhammer.js: Hardware faults from the browser
Summary
Clémentine Maurice and Daniel Gruss show how repeated memory accesses cause DRAM bit flips and how even JavaScript can become a hardware-level attack surface. Rowhammer.js demonstrated a remote, software-induced hardware fault from JavaScript. Abstraction boundaries do not prevent attacks on shared physical resources.
Ideas
- Frequent accesses to DRAM rows can flip bits in neighbouring rows.
- Cache eviction forces the actual memory accesses that are needed.
- JavaScript can trigger precise microarchitectural effects despite its sandbox.
- Through memory layout and repetition, a random bit flip becomes a building block for an exploit.
- Hardware assumptions sit invisibly beneath operating system and browser isolation.
- Side channels and fault attacks exploit shared, observable microarchitecture.
Insights
- Software isolation inherits all the unspoken reliability assumptions of the hardware.
- Remote code does not need privileges to influence physical states in a targeted way.
Quotes
Root privileges for web apps?
– title of the talk
Habits
- Maurice and Gruss reduce the attack to measurable memory and cache operations.
Facts
- Clémentine Maurice and Daniel Gruss gave the talk together.
References
- CCC: Rowhammer.js – Root privileges for web apps?
- Rowhammer: a class of DRAM faults caused by repeated row activation.
- CPU caches: a necessary part of the access technique demonstrated.
Critique
- Exploitability depends heavily on DRAM, platform, browser and countermeasures.
- The title states the maximum consequence in a pointed way, not the effect of every bit flip.
Remarks
- The talk turned what seemed to be a reliability issue into a browser-side security problem.
- Later Rowhammer variants bypassed several of the protections introduced at first.
Recommendations
- Include known hardware faults in sandbox threat models.
- Update firmware, browsers and kernels against known Rowhammer techniques.
- Use ECC as an additional error control, not as the only defence.
Links to the original source and the Web Archive open in a new tab.