CVE-2025-63094: Xiangshan
High severity, CVSS 7.5. EPSS: 0.6% chance of exploitation in the next 30 days.
XiangShan Nanhu V2 and XiangShan Kunmighu V3 were discovered to use speculative execution and indirect branch prediction, allowing attackers to access sensitive information via side-channel analysis of the data cache.
Affected products
- Xiangshan Xiangshan: version 2.0 only; version 3.0 only
Published 2025-12-10. Last modified 2026-06-17.