ETH Zurich Researchers Identify New Security Flaw in Intel Processors

ETH Zurich computer scientists have uncovered a new security vulnerability in Intel processors that exploits speculative execution and puts user data at risk, prompting hardware mitigation updates.

ETH Zurich´s Computer Security Group has discovered a previously unknown class of security vulnerabilities in Intel processors, exposing a critical weakness in how these chips handle speculative execution. The flaw allows an attacker to craft specific sequences of instructions that exploit the processor’s speculation and prediction mechanisms, leading to the breakdown of isolation between users. As a result, an adversary could orchestrate rapid, repeated attacks to read the entire contents of processor memory, posing a significant risk to sensitive information.

The underlying issue stems from speculative execution, a technique built into modern CPUs to enhance performance by predicting and executing likely future instructions. While this prediction-driven approach speeds up computation, it also opens the door for hackers to manipulate speculative behaviors, accessing data that should remain confined to other users. The vulnerabilities identified by ETH Zurich´s team demonstrate that, under specific attack scenarios, these speculative mechanisms can be misused to sidestep existing security boundaries.

In response, Intel has issued a security advisory for CVE-2024-45332 and publicly acknowledged the research, thanking ETH Zurich for their responsible disclosure and collaboration. The company is taking steps to reinforce its Spectre v2 hardware mitigations and advises customers to contact their system manufacturers for firmware or microcode updates. Importantly, Intel states there are currently no known real-world exploits of these transient execution vulnerabilities, but emphasizes that users should remain vigilant and ensure their systems are updated as soon as new mitigations are available.

77

Impact Score

House panel advances export controls after China report

The House Foreign Affairs Committee moved export control legislation after a House Select Committee report detailed China’s use of illegal means to build its Artificial Intelligence and semiconductor sectors. The measure is aimed at chip smuggling and Artificial Intelligence model theft.

Intel repurposes scrap dies to expand CPU supply

Intel is repurposing wafer-edge and lower-yield silicon that would normally be discarded into sellable CPUs as industry demand outpaces supply. The strategy reflects a market where customers are willing to buy lower-tier parts to secure any available capacity.

The missing step between Artificial Intelligence hype and profit

Artificial Intelligence companies have built powerful systems and promised sweeping change, but the path from technical progress to real business value remains unclear. Conflicting studies, weak workplace performance, and poor transparency are leaving a critical gap between hype and evidence.

Samsung workers leaked secrets into ChatGPT

Samsung employees reportedly exposed confidential company information while using ChatGPT for coding help and meeting note generation. The incidents highlight the risk of feeding sensitive data into public Artificial Intelligence tools that retain user inputs.

Contact Us

Got questions? Use the form to contact us.

Contact Form

Clicking next sends a verification code to your email. After verifying, you can enter your message.