Skip to main content

Intel CPUs attacked again as ZombieLoad V2 exploit rises from Spectre’s grave

Intel CPUs that received hardware, software, and microcode fixes for various Spectre-related bugs are still vulnerable to a new speculative execution attack called ZombieLoad v2. This latest flaw in Intel’s chip design doesn’t make every single Core processor vulnerable, but it affects the latest few generations, from 2013’s Haswell architecture through to the latest Cascade Lake designs.

ZombieLoad v2 is the fifth of the micro-architectural data sampling (MDS) vulnerabilities that have affected Intel CPUs. One of those, ZombieLoad, caused concern for every Intel CPU going back to 2011 and Intel was quick to fix it. But that did lead to some performance degradation and raised questions about the viability of Intel’s hyperthreading feature — which enables a CPU to simultaneously work on a number of threads equal to double its number of cores — and whether disabling it altogether might be worth the added security such a performance-inhibiting move would provide.

Recommended Videos

In the case of ZombieLoad V2, Intel was informed of the potential exploit on April 23 of this year, with the researchers behind the discovery confirming that the attack vector was also present on new Cascade Lake CPUs in May. Intel has reportedly not patched this issue at this time, but did release a statement downplaying its potential effects, as well as promising a microcode fix in the near future.

Get your weekly teardown of the tech behind PC gaming
Check your inbox!

“We believe that the mitigations for TAA and MDS substantively reduce the potential attack surface,” Intel said on its new security blog, suggesting that existing ZombieLoad fixes make it unlikely that ZombieLoad V2 would be a viable attack vector. It then went on to claim, however, that, “Shortly before this disclosure […] we confirmed the possibility that some amount of data could still be inferred through a side-channel using these techniques (for TAA, only if TSX is enabled) and will be addressed in future microcode updates. We continuously improve the techniques available to address such issues and appreciate the academic researchers who have partnered with Intel.”

As the researchers pointed out, via WCCFTech, the main problem with ZombieLoad V2 is that it works on CPUs that have hardware fixes against Meltdown. That could suggest that Intel will need to further change its chip designs in future if it wants to put a more permanent stop to these kinds of attacks.

Digital Trends spoke with some chip developers earlier this year who suggested that using a secure core on die could help circumvent the problems faced by speculative execution attacks. It’s too early to tell how effective such a solution would be, but Microsoft recently announced it was incorporating a “Secured core” in its Surface Pro X. We haven’t had extensive testing time with it yet, but the overall design seems solid.

But what about AMD in all this? Since its CPUs don’t use transactional synchronization extensions (TSX) — which enable faster multithreaded software support — it isn’t vulnerable to ZombieLoad-style attacks, in the same way that it wasn’t vulnerable to the initial Meltdown exploit. Indeed, when it comes to chip security and performance-inhibiting mitigations against exploits, AMD is leaps and bounds ahead of Intel. While AMD’s CPUs have slowed down by a few percent since the advent of the first Spectre attacks, Intel hardware with the full complement of fixes has seen far greater performance degradation.

For Intel, things look a little bleaker. Spectre-like attacks seem destined to continue to appear until Intel changes its CPU designs permanently. With AMD breathing down its neck in almost every market sector, that won’t be an attractive prospect, especially since the blue team is already behind on the race to ever-smaller CPU dies.

Jon Martindale
Jon Martindale is a freelance evergreen writer and occasional section coordinator, covering how to guides, best-of lists, and…
Need a budget-friendly laptop? Get this Asus deal at Walmart
The Asus VivoBook 15 laptop open on a white background.

You don't need to spend over a thousand dollars to end up with a dependable device from laptop deals -- you just need to be patient in waiting for a budget-friendly offer that will still provide reliable performance. Here's one: the Asus Vivobook 15 for only $299 from Walmart, following a $100 discount on its original price of $399. We're not sure when it will go back to its regular price though, so we highly recommend finishing your purchase quickly as that could happen at any moment.

Why you should buy the Asus Vivobook 15 laptop
Let's get this out of the way -- at its affordable price, you can't expect the Asus Vivobook 15 to match the performance of the best laptops. The device, however, will prove to be a trustworthy daily companion for regular tasks such as doing online research and typing documents, as well as watching some streaming shows when you're taking a break. It runs on the 12th-generation Intel Core i5 processor, Intel UHD Graphics, and 8GB of RAM, which will be more than enough for these activities. The laptop also ships with a 256GB SSD for ample storage space for your files, and it's got Windows 11 Home pre-installed.

Read more
Apple CEO should do a Steve Jobs on Siri delay, analyst says
Invoking Siri on iPhone.

Apple CEO Tim Cook should go public to explain the delay in integrating advanced Siri capabilities across its ecosystem, rather than Apple releasing the news quietly via a tech site last week, according to prominent Apple analyst Ming-Chi Kuo.

The tech giant showcased an AI-powered Siri at its WWDC event in 2024, as part of its Apple Intelligence initiative. While the virtual assistant does now have some AI smarts, the more advanced features -- including personalized responses, task completion across multiple apps, and on-screen awareness --have been delayed until next year at the earliest.

Read more
Nvidia claims RTX 5000 shipped better than 4000 but gamers are still waiting
The RTX 5090 sitting on a pink background.

Nvidia is trying to make its GeForce RTX 5000 series seem more impressive to the media by suggesting that the latest GPUs are selling better than the previous generation. However, many pundits aren’t buying the claim.

PC Mag pondered whether Nvidia has orchestrated a “paper launch” of the RTX 5000 series, suggesting that there might not be much of a product available for consumers. The majority of the people with their hands on the GPUs, especially the high-end models such as the 5090 and 5080 appear to be reviewers, influencers, and other determined enthusiasts as opposed to everyday gamers, who are still using prior generation GPUs at higher rates.

Read more