Intel 'Downfall' CPU vulnerability exposes sensitive data

Intel Core i5 11400F processor
(Image credit: Future)

A scary new CPU security vulnerability has been revealed. It's called Downfall, and it affects Intel chips beginning with 6th Generation Skylake processors through to 11th Gen Rocket Lake and Tiger Lake.

Downfall was discovered by Google research scientist Daniel Moghimi (via The Register), who posted a webpage dedicated to the issue. Intel has posted about the issue in a security advisory, INTEL-SA-00828.

The flaw relates to the memory optimization features in Intel processors. It can allow certain protected hardware registers to be accessed via software, which is not supposed to be accessible. It does this by taking advantage of the Gather Instructions found in the aforementioned CPUs, which feature AVX2 and AVX-512 support. This means malware can potentially allow access to your applications and software, and possibly steal data including passwords and encryption keys. 

Worryingly, the vulnerability extends to cloud computing operators. Moghimi says: "Similarly, in cloud computing environments, a malicious customer could exploit the Downfall vulnerability to steal data and credentials from other customers who share the same cloud computer." 

AVX instructions are important in many intensive workloads. Various rendering or encoding apps use it, but many sub processes and libraries do too. So while you shouldn't panic, it'll be well worth keeping an eye on your motherboard's product page, and updating the BIOS when it recommends you do so. 

Your next upgrade

Nvidia RTX 4070 and RTX 3080 Founders Edition graphics cards

(Image credit: Future)

Best CPU for gaming: The top chips from Intel and AMD.
Best gaming motherboard: The right boards.
Best graphics card: Your perfect pixel-pusher awaits.
Best SSD for gaming: Get into the game ahead of the rest.

The problem with attacks like this is that an updated BIOS with a microcode fix can drastically reduce performance, and it seems like that's the case here. Some early testing by Phoronix using updated microcode and Linux kernel patches showed big drops in performance.

Gamers are also affected, though given the relatively limited uses of AVX instructions in gaming, the hope is that games won't suffer from performance penalties that compute intensive professional and enterprise software will.

Emulation apps are an area that will be more affected. The RPCS3 PS3 emulator is one that heavily leans on the AVX-512 instruction set, so a performance hit is surely coming.

If you needed an excuse to upgrade to a 12th or 13th Gen system, this might be it. Alder Lake and Raptor Lake processors are not affected.

Chris Szewczyk
Hardware Writer

Chris' gaming experiences go back to the mid-nineties when he conned his parents into buying an 'educational PC' that was conveniently overpowered to play Doom and Tie Fighter. He developed a love of extreme overclocking that destroyed his savings despite the cheaper hardware on offer via his job at a PC store. To afford more LN2 he began moonlighting as a reviewer for VR-Zone before jumping the fence to work for MSI Australia. Since then, he's gone back to journalism, enthusiastically reviewing the latest and greatest components for PC & Tech Authority, PC Powerplay and currently Australian Personal Computer magazine and PC Gamer. Chris still puts far too many hours into Borderlands 3, always striving to become a more efficient killer.

Read more
Pipboy holds up an open padlock.
A BIOS update could be all that's stopping you or someone else from jailbreaking your old AMD CPU
Robert Hallock, VP of CCG at Intel, on stage at CES 2025.
Intel unveils second round of updates intended to bring Arrow Lake desktop chips up to expectations: 'our software for the 200S has reached full performance'
A photo of an Intel Core Ultra 9 285K processor next to an Intel logo
Intel reveals the four fails of Arrow Lake in a new blog post, promising more performance fixes in January
ASRock X870 Steel Legend WiFi motherboard
Reddit reports of 9800X3D CPUs dying in ASRock motherboards are racking up fast, but a new BIOS update seemingly only addresses boot problems
AMD Ryzen 7 9800X3D processor
AMD accuses Intel's Arrow Lake of being a 'horrible' product and implies a lack of options for consumers has caused the Ryzen 7 9800X3D shortage
OC record 1
Core i9 14900KF CPU hits a world record 9.12 GHz and proves Intel chips are still good at something
Latest in Processors
Texas Instruments MSPM0C1104 tiny chip
World's smallest microcontroller looks like I could easily accidentally inhale it but packs a genuine 32-bit Arm CPU
Intel engineers inspect a lithography machine
Finally some good vibes from Intel as stock jumps 15% on new CEO hire and Arizona fab celebrates 'Eagle has landed' moment for its 18A node
A photo of an Intel Core Ultra 9 285K processor surrounded by DDR5 memory sticks from Corsair, Kingston, and Lexar
Fresh leak suggests Intel's on-again-off-again Arrow Lake CPU refresh is back on the menu (boys)
 photo shows a factory tool that places lids on data center system-on-chips at an Intel fab in Chandler, Arizona, in December 2023. In February 2024, Intel Corporation launched Intel Foundry as the world’s first systems foundry for the AI era, delivering leadership in technology, resiliency and sustainability.
Return of the gigahertz wars: New Chinese transistor uses bismuth instead of silicon to potentially sock it to Intel and TSMC with 40% more speed
 photo shows a factory tool that places lids on data center system-on-chips at an Intel fab in Chandler, Arizona, in December 2023. In February 2024, Intel Corporation launched Intel Foundry as the world’s first systems foundry for the AI era, delivering leadership in technology, resiliency and sustainability.
So, wait, now TSMC is supposedly pitching a joint venture with Nvidia, AMD and Broadcom to run Intel's ailing chip fabs?
Pipboy holds up an open padlock.
A BIOS update could be all that's stopping you or someone else from jailbreaking your old AMD CPU
Latest in News
Crying laughing emoji with disturbing realistic elements for REPO
REPO's first update will add a new map and a 'duck bucket' so we can finally give that pesky quacker a time out
Man facing camera
The Day Before studio reportedly sues Russian website for calling infamous disaster-game a 'scam'
Will Poulter holding a CD ROM
'What are most games about? Killing': Black Mirror Season 7 includes a follow-up to 2018 interactive film Bandersnatch
Casper Van Dien in Starship Troopers
Sony, which is making a Helldivers 2 movie, is also making a new Starship Troopers movie, but it's not based on the Starship Troopers movie we already have
Assassin's Creed meets PUBG
Ubisoft is reportedly talking to Tencent about creating a new business entity to manage Assassin's Creed and other big games
Resident Evil Village - Lady Dimitrescu
'It really truly changed my life in every possible way': Lady Dimitrescu actor says her Resident Evil Village role was just as transformative for her as it was for roughly half the internet in 2021