HomeNewsTrendsCybersecurity firms and researchers uncover new Spectre-like flaw in several Intel chips

Cybersecurity firms and researchers uncover new Spectre-like flaw in several Intel chips

If you're thinking of getting Intel's Ivy Bridge, Haswell, Skylake or Kaby Lake processors, consider yourself warned.

May 15, 2019 / 08:14 IST
Story continues below Advertisement

A little over a year after the Meltdown and Spectre flaws found in millions of AMD and Intel chips, a group of security firms and researches discovered a new class of side channel vulnerabilities impacting all Intel CPUs. The security flaw titled 'Zombieload' can potentially leak raw data from a system's CPU.

Like Meltdown, Spectre, and Foreshadow that came before, Zombieload exploits vulnerabilities in Intel's current speculative execution process, an optimisation technique the chipmaker adds to its CPUs to improve data processing speeds and performance.

Story continues below Advertisement

Experts have been pointing out flaws in Intel's speculative execution process for over a year now, exposing ways data can be leaked through CPU buffer zones and data processing operations.

Today, Intel and a team of academic researchers have termed this new form of hackable vulnerability in Intel's chips – previously labelled as Zombieload – as a Microarchitectural Data Sampling (MDS) attack. The MDS issue is a speculative execution side-channel attack that allows an attacker to locally execute code to target the CPU's micro-architectural data structures, which are otherwise protected by Intel's processor architectural mechanisms. This technique could allow a malicious actor to siphon a stream of potentially sensitive data.