Skip to main content

Digital Trends may earn a commission when you buy through links on our site. Why trust us?

Billions of Intel CPUs are leaking passwords and killing performance

An Intel processor over a dark blue background.
Intel

A scary vulnerability has recently been discovered in some Intel processors, and while the best CPUs are not affected, billions of chips could be. According to the researcher who first spotted the Downfall vulnerability, “everyone on the internet is affected.” This is made worse by the fact that a skilled hacker could steal some of the most sensitive data from affected computers, including passwords.

Recommended Videos

Downfall was discovered by a senior research scientist from Google, Daniel Moghimi, who created a page dedicated to it, detailing how it works and what it can possibly do. Downfall targets the Gather Instruction in Intel chips, which normally helps the CPU quickly access various data spread all over different parts of its memory. However, with the flaw, internal hardware registers can be exposed to software. If the software is compromised, it’s possible that hackers could seize sensitive data from the PC.

The affected CPUs all belong to Intel’s mainstream and server processor lineups, starting from Skylake all the way up to Rocket Lake. This means that, unless you’ve upgraded your CPU in the last few years, you’re definitely affected, but you can check out Intel’s full list of chips that are vulnerable.

As Moghimi notes,  you don’t even need to own an Intel processor to potentially be affected. As Intel dominates the server market, cloud computing environments might be hit by this as well, where “malicious customer could exploit the Downfall vulnerability to steal data and credentials from other customers who share the same cloud computer,” says Moghimi.

While pulling off an actual hack with Downfall seems tricky, there’s a lot at stake, which is why Intel has already released a fix — but the downside is a massive performance loss. Intel was quick to say it would be releasing new microcode for the chips that are affected, and it recommended that users update their firmware to prevent being affected by Downfall. It’s here now, but as noted by Phoronix, the price to pay for not having your password leaked is massive.

A person using a laptop with a set of code seen on the display.
Sora Shimazaki / Pexels

Intel itself estimated a performance loss of up to 50%, with AVX instructions most affected. The good news is that for most users, this won’t be an issue, but the bad news is that AI-related workloads and overall high-performance computing (HPC) tasks are hit pretty hard.

Phoronix tested the impact on Linux with four different CPUs, including a Xeon Platinum 8380, Xeon Gold 6226R, and an Intel Core i7-1165G7. Performance losses range from 6% up to 39%, which, while not as bad as Intel predicted, is still not great.

You don’t need to update your processor if you’re not worried about being affected by Downfall. While Moghimi recommends it, Intel itself allows users to opt out of the extra mitigation in order to restore the full performance of their CPU. If you’re not using your PC for HPC tasks, it sounds like you might as well keep the mitigation on, but Intel has detailed the process of turning it off if you’d rather get rid of it.

Monica J. White
Monica is a computing writer at Digital Trends, focusing on PC hardware. Since joining the team in 2021, Monica has written…
Intel is bringing back one of its most frustrating types of CPUs
Intel Core Ultra Series 2 Lunar Lake chipset.

Intel's new Arrow Lake CPUs are a big deal. They utilize an entirely new architecture and come with a new socket, which will help them compete for a spot among the best processors. However, it looks like some upcoming Core 200-series CPUs (the non-Ultra versions) might not use the Arrow Lake/Lunar Lake architecture at all -- they might be rebranded CPUs sporting older CPU tech.

The assumption comes from results in the Crossmark benchmark that were posted to Bapco and first pointed out by Everest on X (formerly Twitter). The result shows the Core 5 210H, but it's not the performance that's interesting. It's the specs. The result shows that the CPU comes with eight cores and 12 threads. That's the rub. Arrow Lake and Lunar Lake don't come with Hyper-Threading, so each core only comes with a single thread.

Read more
Sorry, gamers — Intel’s new CPUs won’t deliver any gains
A render for an Intel Arrow Lake CPU.

Intel is setting expectations for its upcoming Arrow Lake-S desktop CPUs. Although the company is holding strong that the new generation will be competitive with the best processors when they release on October 24, the new range of CPUs won't deliver much, if any, performance gains for gamers -- and that's coming from Intel itself.

To kick off the Arrow Lake generation, now called Intel Core Ultra 200S, Intel is releasing five processors. You can see the standard Core Ultra 9, 7, and 5 models in the table below, along with Core Ultra 7 and 5 models that cut the integrated graphics for a slightly lower price. All five of the processors are unlocked for overclocking with the new LGA 1851 socket. Unlike AMD's new Zen 5 CPUs, Core Ultra 200S chips require a new motherboard as Intel retires its LGA 1700 socket.

Read more
Intel did the unthinkable with its new Arrow Lake CPUs
A render of an Intel Core Ultra 200-S chip.

It finally happened. Intel killed Hyper-Threading on its desktop CPUs. The new Arrow Lake range, called Core Ultra 200S, ditches the simultaneous multi-threading (SMT) feature that Intel has held onto for more than a decade. And according to Intel, it doesn't need the extra threads to still deliver a generational performance improvement, even up against the best processors.

Intel says the new range, which we break down in detail in our post focused its gaming potential, can deliver an 8% performance improvement in single-threaded workloads over the previous generation, and a 4% uplift compared to the Ryzen 9 9950X. Those are pretty small margins, but the real impressive stuff comes in multi-threaded performance.

Read more