• News/
  • https://www.bleepingcomputer.com/news/security/new-intel-cpu-flaws-leak-sensitive-data-from-privileged-memory/

New Intel CPU flaws leak sensitive data from privileged memory

BleepingComputer
·
Bill Toulas
·
Published May 13, 2025
·
Updated

A new "Branch Privilege Injection" flaw in all modern Intel CPUs allows attackers to leak sensitive data from memory regions allocated to privileged software like the operating system kernel. Typically, these regions are populated with information like passwords, cryptographic keys, memory of other processes, and kernel data structures, so protecting them from leakage is crucial. According to ETH Zurich researchers Sandro Rüegge, Johannes Wikner, and Kaveh Razavi, Spectre v2 mitigations held for six years, but their latest "Branch Predictor Race Conditions" exploit effectively bypasses them. The flaw, which is named 'branch privilege injection' and tracked under CVE-2024-45332, is a race condition on the subsystem of branch predictors used in Intel CPUs. Branch predictors like Branch Target Buffer (BTB) and Indirect Branch Predictor (IBP) are specialized hardware components that try to guess the outcome of a branch instruction before it's resolved to keep the CPU pipeline full for optimal performance. These predictions are speculative, meaning they are undone if they end up being wrong. However, if they are correct, it increases performance. The researchers found that Intel's branch predictor updates are not synchronized with instruction execution, resulting in these updates traversing privilege boundaries. If a privilege switch happens, like from user mode to kernel mode, there is a small window of opportunity during which the update is associated with the wrong privilege l...

Read full article

Affected Software

9 affected components
Intel CPU=9th generation
Intel CPU=Coffee Lake
Intel CPU=Comet Lake
Intel CPU=Rocket Lake
Intel CPU=Alder Lake
Intel CPU=Raptor Lake
Intel CPU=7th generation
Intel CPU=Kaby Lake
Intel CPU
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses newly discovered vulnerabilities in Intel CPUs that allow attackers to leak sensitive data from privileged memory.

2

What types of security risks are associated with the new Intel CPU flaws?

The security risks include the potential for sensitive data exposure from memory regions allocated to critical software such as the operating system kernel.

3

Which Intel CPU generations are affected by the vulnerabilities?

The vulnerabilities impact multiple Intel CPU generations including 7th, 9th, Coffee Lake, Comet Lake, Rocket Lake, Alder Lake, and Raptor Lake.

4

What is the specific name of the newly identified flaw?

The newly identified flaw is referred to as the "Branch Privilege Injection" vulnerability.

5

Who is primarily affected by these Intel CPU vulnerabilities?

Organizations and individuals using affected Intel CPUs in their systems may be at risk of data leakage due to these vulnerabilities.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203