A virtual machine (VM) vulnerability that compromises AMD Zen and Intel Coffee Lake CPUs has been discovered.
Revealed last month by researchers at ETH Zürich who described it as the first of its kind, the vulnerability affects processors by circumventing the virtualization layer in a cloud setup.
Known as VMScape (CVE-2025-40300), the exploit allows a threat actor to VM Exit – break out of their cloud-hosted VM – and expose secrets in the host machine's hypervisor without once altering its default configuration.
With this breaking of the barriers, the bug challenges a major tenet of virtualization that there is a silo of sorts between a guest virtual machine and its hypervisor/host in the branch predictor domain.
It is also an example of a Spectre attack, which exploits a major hardware flaw found in most modern CPUs that use a performance optimization technique called speculative execution. Malicious code is able to trick the processor into leaking sensitive data from a victim program via the CPU’s memory cache, specifically by training the branch predictor (BTB) in a controlled way. Such attacks have affected Intel, AMD, and Arm CPUs over the years.
The researchers showed this virtualization compromise capability against Linux hosts using KVM (Kernel-based Virtual Machine) and QEMU (Quick EMUlator). The affected CPUs tested for the report include AMD Zen 1–5 and several Intel Coffee Lake iterations across the Skylake, Cascade, and Alder Lake families.
Revealed were measured leakage rates in the tens of bytes per second on affected hardware, sufficient enough to extract small high-value secrets such as encryption keys over time.
According to Linux Journal, the Linux kernel has since been updated to mitigate the threat through the use of predictor barriers, a hardware-level patch for speculative execution vulnerabilities.
To protect a host system from a malicious virtual machine using the Spectre exploit, the kernel uses an Indirect Branch Prediction Barrier (IBPB) to reset the CPU's speculative execution data every time it switches control from the VM back to the host.
A boot option known as vmscape= can control how and when this fix is applied, for example, every time a VM exits, or only when certain conditions are met.
For setups with multiple virtual cores, known as hyperthreads, the system may also recommend other settings, such as enabling a Single Thread Indirect Branch Predictor (STIBP) or disabling hyperthreading altogether, to prevent information from leaking between the cores.
Administrators were advised to update kernels and virtualization components, check the VMScape vulnerability status, enable appropriate IBPB/STIBP policies or disable SMT on sensitive hosts, and check with cloud providers what security options are available.
The VMScape threat follows recent Microsoft research, which uncovered a series of security flaws in AMD processors.
Their findings showed that AMD’s Epyc processors contained four vulnerabilities that could be used to access protected information. Among the flaws found was a cross-VM leak, where an attacker could retrieve data from another virtual machine bit by bit, similar to the VMScape exploit.
Comments