Intel confirms that Alder Lake BIOS code has been leaked but expects no new security flaws

Intel Core i9 12900K up-close images with the chip exposed
(Image credit: Future)

Intel has confirmed that its proprietary UEFI code for its 12th Gen processors has been leaked. The 6GB file, published to 4chan and Github, contains information regarding the creation and optimisation of BIOS code for Alder Lake chips, however, Intel does not suspect this will expose any new security vulnerabilities. 

"Our proprietary UEFI code appears to have been leaked by a third party," an Intel spokesperson says to Tom's Hardware

"We do not believe this exposes any new security vulnerabilities as we do not rely on obfuscation of information as a security measure. This code is covered under our bug bounty program within the Project Circuit Breaker campaign, and we encourage any researchers who may identify potential vulnerabilities to bring them our attention through this program. We are reaching out to both customers and the security research community to keep them informed of this situation."

It appears as though Intel's strategy is to avoid having any 'secret code' as a part of its processor security. I imagine that's to primarily avoid a situation like this one today, where said code could, if in the wrong hands, make mincemeat of its processor security. The company does sound quite confident that this leak shouldn't pose any security threat as a result.

Intel's statement suggests a third party is responsible for the files getting out there, rather than a hack of its own internal systems. As Twitter user SttyK and the Tom's Hardware report note, the Github repository was created by an employee at LC Future Center, a China-based laptop manufacturer, and parts of the code mention Lenovo, one of LC Future Center's clients. However, this connection has not been confirmed by Intel or elsewhere.

The exposed UEFI files will still cause concern to security researchers, even if ultimately Intel feels its CPUs will still be safe from nefarious actors. The UEFI works in tandem with the OS to deliver on fundamental security principles within Windows and to ensure that exploits don't gain access to private information. It already appears that security researchers are paying close attention to the leaked files to see what they can uncover.

Those that uncover any vulnerabilities in the code may be in line for a cash reward, too. Intel mentions that the code is covered by its Project Circuit Breaker campaign, which is another name for its bug bounty program. There's a specific "Code Challenge" in place for this particular BIOS leak. It's called "Alders & Seekers".

Your next upgrade

(Image credit: Future)

Best CPU for gaming: The top chips from Intel and AMD
Best gaming motherboard: The right boards
Best graphics card: Your perfect pixel-pusher awaits
Best SSD for gaming: Get into the game ahead of the rest

"Due to the unauthorized disclosure of Intel’s proprietary UEFI code for Alder Lake we are opening the private Alders & Seekers bug bounty campaign to all security researchers. In addition, we have extended the end date of this campaign from October 15, 2022 to 9AM US eastern time on January 20, 2022.  The standard Intel(R) Bug Bounty Program policy applies to this campaign."

So if there are any holes in Alder Lake's security that arise from this leak, here's hoping they'll be patched up before they're more widespread as a result of the bug bounty. These programs can pay handsomely, depending on the severity of the bug, which often attracts some skilled security experts into helping out.

In the meantime, this shouldn't be cause of any immediate concern for PC gamers rocking an Intel Core i9 12900K or other 12th Gen processor. So don't fret. If there is any such cause for concern in the future, making sure you've kept your system up to date and running the latest mitigations will often prove the best defence against these sorts of exploits.

Jacob Ridley
Managing Editor, Hardware

Jacob earned his first byline writing for his own tech blog. From there, he graduated to professionally breaking things as hardware writer at PCGamesN, and would go on to run the team as hardware editor. He joined PC Gamer's top staff as senior hardware editor before becoming managing editor of the hardware team, and you'll now find him reporting on the latest developments in the technology and gaming industries and testing the newest PC components.

Read more
Pipboy holds up an open padlock.
A BIOS update could be all that's stopping you or someone else from jailbreaking your old AMD CPU
A photo of an Intel Core Ultra 9 285K processor next to an Intel logo
Intel reveals the four fails of Arrow Lake in a new blog post, promising more performance fixes in January
Robert Hallock, VP of CCG at Intel, on stage at CES 2025.
Intel unveils second round of updates intended to bring Arrow Lake desktop chips up to expectations: 'our software for the 200S has reached full performance'
A photo of an Intel Core Ultra 9 285K processor surrounded by DDR5 memory sticks from Corsair, Kingston, and Lexar
Fresh leak suggests Intel's on-again-off-again Arrow Lake CPU refresh is back on the menu (boys)
A photograph of Intel's Interim Co-CEO Michelle Johnston Holthaus standing on stage, with a background displaying Panther Lake and Intel 18A
Intel says next-gen Panther Lake laptop chips on its new 18A silicon are still on track for later this year but things are more complicated on the desktop
Bill Gates speaks onstage for a special conversation during "What’s Next? The Future With Bill Gates"at The Paris Theater on September 26, 2024 in New York City.
Bill Gates laments Pat Gelsinger's failure to save Intel: 'I was hoping for his sake, for the country's sake that he would be successful'
Latest in Processors
Texas Instruments MSPM0C1104 tiny chip
World's smallest microcontroller looks like I could easily accidentally inhale it but packs a genuine 32-bit Arm CPU
Intel engineers inspect a lithography machine
Finally some good vibes from Intel as stock jumps 15% on new CEO hire and Arizona fab celebrates 'Eagle has landed' moment for its 18A node
A photo of an Intel Core Ultra 9 285K processor surrounded by DDR5 memory sticks from Corsair, Kingston, and Lexar
Fresh leak suggests Intel's on-again-off-again Arrow Lake CPU refresh is back on the menu (boys)
 photo shows a factory tool that places lids on data center system-on-chips at an Intel fab in Chandler, Arizona, in December 2023. In February 2024, Intel Corporation launched Intel Foundry as the world’s first systems foundry for the AI era, delivering leadership in technology, resiliency and sustainability.
Return of the gigahertz wars: New Chinese transistor uses bismuth instead of silicon to potentially sock it to Intel and TSMC with 40% more speed
 photo shows a factory tool that places lids on data center system-on-chips at an Intel fab in Chandler, Arizona, in December 2023. In February 2024, Intel Corporation launched Intel Foundry as the world’s first systems foundry for the AI era, delivering leadership in technology, resiliency and sustainability.
So, wait, now TSMC is supposedly pitching a joint venture with Nvidia, AMD and Broadcom to run Intel's ailing chip fabs?
Pipboy holds up an open padlock.
A BIOS update could be all that's stopping you or someone else from jailbreaking your old AMD CPU
Latest in News
Man facing camera
The Day Before studio reportedly sues Russian website for calling infamous disaster-game a 'scam'
Will Poulter holding a CD ROM
'What are most games about? Killing': Black Mirror Season 7 includes a follow-up to 2018 interactive film Bandersnatch
Casper Van Dien in Starship Troopers
Sony, which is making a Helldivers 2 movie, is also making a new Starship Troopers movie, but it's not based on the Starship Troopers movie we already have
Assassin's Creed meets PUBG
Ubisoft is reportedly talking to Tencent about creating a new business entity to manage Assassin's Creed and other big games
Resident Evil Village - Lady Dimitrescu
'It really truly changed my life in every possible way': Lady Dimitrescu actor says her Resident Evil Village role was just as transformative for her as it was for roughly half the internet in 2021
Storm trooper hero
Another live service shooter is getting shut down, this time before it even launched on Steam