Skip to main content
  1. Home
  2. Computing
  3. News

Digital Trends may earn a commission when you buy through links on our site. Why trust us?

The Spectre flaw is back — and Intel Alder Lake isn’t safe

Intel CPUs have been subjected to several significant security vulnerabilities in recent years, namely Meltdown and Spectre. Now, the latter has made an appearance once again.

As reported by Tom’s Hardware and Phoronix, security research group VUSec and Intel confirmed the existence of a new speculative execution vulnerability labeled branch history injection (BHI).

An Intel Alder Lake pin layout.
Image used with permission by copyright holder

Classified as a by-product of Spectre V2, BHI is a proof-of-concept exploit capable of leaking arbitrary kernel memory on Intel CPUs. As a result, sensitive data such as passwords can be extracted. Intel processors released in the past few years, which includes its latest 12th-generation Alder Lake processors, are said to be affected.

Recommended Videos

Certain ARM silicon have also been found to be vulnerable to the exploit. As for AMD CPUs, security researchers initially found that they remain immune to potential BHI attacks. However, there have been some developments in this area that appear to suggest otherwise.

“The LFENCE-based mitigation is deemed no longer sufficient for mitigating Spectre V2 attacks. Now the Linux kernel will use return trampolines “retpolines” by default on all AMD processors,” Phoronix explained. “Various AMD CPUs have already defaulted to using Retpolines for Spectre V2 mitigations, while now it will be the default across the board for AMD processors.”

Vusec provided further insight into how the exploit can find its way through mitigations that are already in place. While hardware mitigations prevent an attacker from injecting predictor entries for the kernel, they can still make use of a global history in order to select target entries to speculatively execute. “And the attacker can poison this history from Userland to force the kernel to mispredict to more “interesting” kernel targets (i.e., gadgets) that leak data,” the report added.

Intel has published a list of CPUs affected by the exploit, confirming that several generations of chips ranging back to 2013 (Haswell) can be infiltrated, including Coffee Lake, Tiger Lake, Ice Lake, and Alder Lake. Ice Lake servers were also mentioned on the list.

Chips from ARM, including Neoverse N2, N1, V1, Cortex A15, A57, and A72, have all been found to be impacted as well. Depending on the system on a chip, the chip designer is issuing five different mitigations.

Intel is expected to release a software patch to address the new Spectre-based BHI exploit. In the interim, the chipmaker provided Phoronix with a statement on BHI in regard to its impact on Linux systems:

“The attack, as demonstrated by researchers, was previously mitigated by default in most Linux distributions. The Linux community has implemented Intel’s recommendations starting in Linux kernel version 5.16 and is in the process of backporting the mitigation to earlier versions of the Linux kernel.”

When Spectre and Meltdown were originally discovered as a CPU vulnerability in 2018, lawsuits began to be filed against Intel, alleging the company knew about the flaws but kept silent about them while still selling the silicon in question. As pointed out by Tom’s Hardware, by mid-February 2018, a total of 32 lawsuits were filed against Team Blue.

Intel recently introduced an expansion of its existing Bug Bounty program with Project Circuit Breaker, an initiative directed toward recruiting “elite hackers.” Discovering bugs in firmware, hypervisors, GPUs, chipsets, and other areas could result in a financial windfall for participants, with payouts potentially reaching the six-figure range.

Zak Islam
Former Contributor
Zak covers the latest news in the technology world, particularly the computing field. A fan of anything pertaining to tech…
Google Lens is becoming part of Chrome’s native AI interface
Google is testing a new AI-powered side panel experience in Chrome
Google Lens brings visual searches to the phone.

Google is trying out a major tweak to how AI works inside Chrome, specifically by mashing up Google Lens with the browser's native AI side panel. Right now, this is popping up in Chrome Canary - the experimental playground where Google tests new features before they go mainstream.

The big shift here is that Lens isn't just acting as a standalone tool for looking up images anymore. Instead, it now triggers Chrome's full AI interface right in the side panel, blending image search, page reading, and chat into one unified spot.

Read more
You can now ask Gemini questions about your NotebookLM notebooks
The NotebookLM integration is currently limited to Gemini on the web.
NotebookLM research results

We recently learned that Google was prepping a new feature that would allow users to ask Gemini questions about their NotebookLM notebooks. Although Google still hasn't made anything official, this feature now appears to be rolling out to users.

According to recent X posts from Sai Nemani and TestingCatalog, the attachment menu in Gemini on the web now includes a NotebookLM button. This option lets users attach a notebook and ask Gemini questions about the attached notebook to get more relevant responses.

Read more
Asus is now offering the Nvidia GeForce RTX 5060 in two new flavors
New RTX 5060 EVO cards introduce a slimmer 2.1-slot design
asus-nvidia-GeForce-RTX-5060-evo

ASUS has quietly added two new models to its GeForce RTX 5060 lineup that look almost identical to existing cards at first glance but come with several hardware tweaks. Without any formal announcement, ASUS has listed the Dual GeForce RTX 5060 EVO and Dual GeForce RTX 5060 Ti EVO on its website. These cards sit alongside the standard RTX 5060 and 5060 Ti, offering the same core performance while reworking the physical design and internal layout.

The most noticeable change is size. Both EVO cards use a slimmer 2.1 slot design instead of the 2.5 slot layout used by earlier versions, making them more suitable for compact PC builds. ASUS also redesigned the PCB to use a shorter PCIe x8 edge connector rather than a full length x16 connector (via Vortez).

Read more