Intel Downfall Security Flaw Affecting Older Chips Discovered by Researcher, Chipmaker Rolls Out Fixes

Downfall has impacted users for at least nine years as the affected chips date back to 2014, according to the security researcher who discovered the flaw.

Advertisement
Written by David Delima, Edited by Siddharth Suvarna | Updated: 9 August 2023 17:42 IST
Highlights
  • Intel has issued security fixes for a flaw affecting its older CPUs
  • The Downfall vulnerability affects chips that are up to nine years old
  • Intel revealed details about the security flaws on August 8
Intel Downfall Security Flaw Affecting Older Chips Discovered by Researcher, Chipmaker Rolls Out Fixes

Downfall can also bypass fixes previously issued by Intel for older flaws like Meltdown

Photo Credit: Reuters

Intel processors are affected by Downfall, a security flaw that can allow a malicious user to gain access to sensitive and private user data from users' computers, and the chipmaker is rolling out fixes that patch the vulnerability on affected systems. The flaw was detected by a California-based researcher and disclosed to Intel, allowing the firm to patch the issue before details were published online. Unlike the company's recent chips, older CPUs released by Intel in 2015 are currently vulnerable and these models will receive a microcode update to fix the potential leakage of information.

The chipmaker has assigned a "Medium" security rating for the bug in a post on the Intel Security website, which states that the firm will issue a firmware update and a software sequence — the latter is optional — that is designed to patch the security flaw. Customers with PCs powered by Intel's 6th generation Skylake processors all the way up to the 11th generation Tiger Lake processors are affected by the security flaw. Alder Lake, Sapphire Rapids, and Raptor Lake chips are not affected by the flaw.

Dubbed Downfall by Daniel Moghimi, the Google security researcher who discovered it, the vulnerability is capable of beating boundaries set by the chipmaker for the operating system, virtual machine, and Intel's Software Guard Extensions. Moghimi used the Gather instruction that is used to make it easier to access data that is scattered in the device's memory in order to discover the flaw and develop a proof of concept that was shared with the company in order to develop a fix.

The researcher also explains that the Downfall vulnerability can also bypass fixes previously issued by Intel for older flaws such as Meltdown and Microarchitectural Data Sampling (MDS). Intel is rolling out microcode updates to secure its older processors against the flaw that can allow an attacker to steal arbitrary data from the Linux Kernel, 128-bit and 256-bit AES keys from another user, and even spy on printable characters, according to Moghimi.

Advertisement

Moghimi says the Downfall vulnerability is "highly practical" and that developing an end-to-end attack to steal encryption keys from OpenSSL — and open-source encryption library — took only two weeks. Users have been exposed to Downfall for at least nine years, as the chips affected by the security flaw were released as early as 2014.

“The security researcher, working within the controlled conditions of a research environment, demonstrated the GDS issue which relies on software using Gather instructions. While this attack would be very complex to pull off outside of such controlled conditions, affected platforms have an available mitigation via a microcode update. Recent Intel processors, including Alder Lake, Raptor Lake and Sapphire Rapids, are not affected. Many customers, after reviewing Intel's risk assessment guidance, may determine to disable the mitigation via switches made available through Windows and Linux operating systems as well as VMMs. In public cloud environments, customers should check with their provider on the feasibility of these switches,” an Intel spokesperson told Gadgets 360.


From the launch of the Infinix GT 10 Pro to Amazon's latest mega-sale, we discuss the most noteworthy technology news events of the week on the latest episode of Orbital, the Gadgets 360 podcast. Orbital is available on Spotify, Gaana, JioSaavn, Google Podcasts, Apple Podcasts, Amazon Music and wherever you get your podcasts.
Affiliate links may be automatically generated - see our ethics statement for details.
 

For the latest tech news and reviews, follow Gadgets 360 on X, Facebook, WhatsApp, Threads and Google News. For the latest videos on gadgets and tech, subscribe to our YouTube channel. If you want to know everything about top influencers, follow our in-house Who'sThat360 on Instagram and YouTube.

Advertisement

Related Stories

Popular Mobile Brands
  1. Apple Announces iOS 26 With Liquid Glass Design, These New Features
  2. ChatGPT Down: Users Report Problems While Generating Responses
  3. Motorola Edge 60 With 5,500mAh Battery Launched in India: Price, Offers
  4. Samsung Galaxy Z Fold 7 Claimed to Be Thinnest, Lightest Foldable to Date
  5. iOS 26, iPadOS 26 Are Compatible With These iPhone and iPad Models
  6. Everything We Know About the Vivo T4 Ultra Ahead of Its June 11 Launch
  7. Vivo T4 Ultra Chipset, Display Features Confirmed Ahead of India Launch
  8. Xcode 26 Will Let Developers Write Code With ChatGPT and Other AI Models
  9. Tata Motors to Invest up to $4 Billion Over Five Years for EVs, New Cars
  10. Oppo K13x 5G Price Range in India, Retail Box Leaked Online
  1. ChatGPT Down: Thousands of Users Report Problems While Generating Responses on OpenAI’s Chatbot
  2. Hollow Knight: Silksong Will Release Before Holiday 2025, Not Tied to Xbox Ally Launch, Developer Says
  3. Samsung Galaxy S25 Ultra Allegedly Saves Life by Stopping Shrapnel; Samsung Offers Free Repair
  4. WWDC 2025: Xcode 26 Adds ChatGPT Integration, Support for Other AI Models
  5. Vivo Y400 Pro Design, Key Specifications Leaked; Tipped to Get Dimensity 7300 SoC, 5,500mAh Battery
  6. Motorola Edge 60 With MediaTek Dimensity 7400 SoC, Triple Rear Cameras Launched in India: Price, Features
  7. iPadOS 26 Brings Improved Multitasking With New Windowing System, Menu Bar, and More
  8. WWDC 2025: visionOS 26 Announced With Improvements to Personas and New Spatial Features
  9. Samsung Galaxy Z Fold 7 Teased; Claimed to Be Slimmest, Lightest, and Most Advanced Foldable Yet
  10. Konami to Host Livestream Focussed on Metal Gear Solid Delta: Snake Eater and Silent Hill f This Week
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.