Skip to main content

CPU owners are suing Intel. Here’s the surprising reason why

Promotional image of an Intel Core desktop processor.
Intel

Five unhappy owners of Intel CPUs have just started a class action lawsuit against the company following the discovery that, allegedly, Intel knowingly sold processors affected by a dangerous vulnerability — and it has been doing this for years. The flaw in question is called Downfall, and while it doesn’t affect Intel’s best CPUs, it’s present in chips ranging from the 6th to the 11th generation of Intel processors.

Dating back to Skylake CPUs and still present in Rocket Lake chips, the Downfall vulnerability was first made public by security researcher Daniel Moghimi. This flaw targets the Gather Instruction process in Intel CPUs. Normally, this allows the CPU to quickly access various data in its memory, but unfortunately, this also means that any vulnerabilities within Gather Instruction grant the threat actor a lot of access to the affected PC. Be it through malware or by direct access, attackers could potentially steal a lot of sensitive data from affected chips.

Intel issued a patch to prevent the bug, but it came at a huge cost. As reported by Tom’s Hardware, downloading the patch slowed down AVX2 and AVX-512 workloads by up to 50%. This left users stuck in a lose-lose situation where they could either make themselves vulnerable to Downfall or patch the CPU and suffer from the performance loss. The plaintiffs disagree with this approach from Intel and are now demanding a jury trial at the U.S. District Court in San Jose.

First reported on by The Register, the class action suit has five plaintiffs who own one of the chips that are affected by Downfall. According to the suit, Intel was made aware of the vulnerability all the way back in 2018, when Intel was already dealing with other threats, namely Spectre and Meltdown. Third-party researchers prepared vulnerability reports about the yet-unnamed downfall back then, finding a flaw within the AVX instruction set in a similar manner to Spectre and Meltdown.

Alexander Yee, a hardware enthusiast, prepared a write-up about the flaw in 2018 and delayed publishing it until August 7, 2018, reportedly at Intel’s request. Due to this, the plaintiffs believe that Intel should have addressed Downfall in 2018 when it was first informed about the flaw instead of proceeding to sell the chips as-is.

Intel CEO Pat Gelsinger delivers the Day 1 closing keynote at IAA Mobility.
Intel

“Despite promising a hardware redesign to mitigate speculative execution vulnerabilities during the exact time period researchers disclosed the vulnerabilities in Intel’s AVX instructions, Intel did nothing. It did not fix its then-current chips, and over three successive generations, Intel did not redesign its chips to ensure that AVX instructions would operate securely when the CPU speculatively executed them,” says the complaint.

The document also talks about the five affected plaintiffs, with one person in particular saying that she “would not have purchased her Intel CPUs at the price she paid had she known about the defect described in this Complaint.”

The complaint also outlines what the plaintiffs are after: “Intel’s affected CPUs — billions of them — are to this day defectively designed, and Intel has instituted no recall, implemented no repair program, and provided no plan to fix the underlying design defect. Plaintiffs seek damages and equitable relief.”

Intel has declined to comment on these allegations thus far. It’s hard to say where this can go, and with these CPUs being a few generations old by now, they’re hard to find in stores at this point. However, those who already own them still face a difficult choice: To update or not to update? Intel itself recommends updating, but if you often use your CPU to run AVX2 and AVX-512 workloads, you might experience severe drops in performance.

Editors' Recommendations

Monica J. White
Monica is a UK-based freelance writer and self-proclaimed geek. A firm believer in the "PC building is just like expensive…
Billions of Intel CPUs are leaking passwords and killing performance
An Intel processor over a dark blue background.

A scary vulnerability has recently been discovered in some Intel processors, and while the best CPUs are not affected, billions of chips could be. According to the researcher who first spotted the Downfall vulnerability, "everyone on the internet is affected." This is made worse by the fact that a skilled hacker could steal some of the most sensitive data from affected computers, including passwords.

Downfall was discovered by a senior research scientist from Google, Daniel Moghimi, who created a page dedicated to it, detailing how it works and what it can possibly do. Downfall targets the Gather Instruction in Intel chips, which normally helps the CPU quickly access various data spread all over different parts of its memory. However, with the flaw, internal hardware registers can be exposed to software. If the software is compromised, it's possible that hackers could seize sensitive data from the PC.

Read more
Intel Core i5 vs. i7: Which CPU is right for you in 2023?
Intel Core i5-12400F box sitting in front of a gaming PC.

Intel's Core i5 and i7 CPUs continue to be the most popular choice in the realm of processors, and rightfully so. But understanding the distinctions between them is not a straightforward task. Similar to numerous other computer components, there are various models within each tier, which can potentially lead to a somewhat overwhelming selection process.

We're here to break down all the differences between Intel's Core i5 and Core i7 CPUs, both on desktop and mobile. They're closer than they were in previous years, and rumor has it that the naming scheme will be replaced outright later this year. But for now, it's still an important comparison to wrap your mind around if you're in the market.
Intel Core i5 vs i7: what’s the difference?

Read more
Intel thinks your next CPU needs an AI processor — here’s why
The Intel Meteor Lake chip.

Intel thinks your next processor upgrade should include a dedicated AI processor and its upcoming Meteor Lake chips conveniently fill that gap. The company detailed how it suspects its Vision Processing Units (VPUs) will be leveraged at Computex 2023, and it's including these processors stock on every Meteor Lake chip.

The VPU isn't new. Intel introduced this dedicated AI processor with its 13th-gen Raptor Lake processors, but only on a select few models. The company says they'll come on all Meteor Lake chips, which are slated to launch at the end of 2023.

Read more