PortSmash vulnerability hits Intel CPUs

Some of Intel's most popular chips have been hit by a major security flaw, researchers have claimed.

This vulnerability, named PortSmash, has been discovered by a team of academics from Tampere University of Technology in Finland and Technical University of Havana Cuba.

PortSmash is impacting some of Intel's most well-known processors, including the Kaby Lake and Skylake units found in many laptops on the market today, and could potentially allow attackers to leak encrypted data from the CPU’s internal processes.

Intel CPU threat

Specifically, PortSmash targets a flaw in Intel's hyperthreading technology, which cuts down on the time needed for a device to carry out high-end computing tasks.

The researchers where able to exploit a leak in the hyperthreading system to access secure private keys from servers running Skylake and Kaby Lake processors by tracking specific computing processes in order to deduce the key.

The flaw affects both servers and PCs, the researchers said, although the former is more at risk, which could prove dangerous for cloud providers who offer infrastructure-as-a-service (IaaS) platforms, as servers, storage and networking hardware could be targeted in a single shot.

Intel has responded to the report, noting that it expects that the threat it "is not unique" to its platforms alone. 

"Protecting our customers’ data and ensuring the security of our products is a top priority for Intel and we will continue to work with customers, partners and researchers to understand and mitigate any vulnerabilities that are identified," the company added.

Via: ArsTechnica

TOPICS
Mike Moore
Deputy Editor, TechRadar Pro

Mike Moore is Deputy Editor at TechRadar Pro. He has worked as a B2B and B2C tech journalist for nearly a decade, including at one of the UK's leading national newspapers and fellow Future title ITProPortal, and when he's not keeping track of all the latest enterprise and workplace trends, can most likely be found watching, following or taking part in some kind of sport.

Latest in Pro
Zendesk Relate 2025
Zendesk Relate 2025 - everything you need to know as the event unfolds
Microsoft
"Another pair of eyes" - Microsoft launches all-new Security Copilot Agents to give security teams the upper hand
Lock on Laptop Screen
Medusa ransomware is able to disable anti-malware tools, so be on your guard
AI quantization
What is AI quantization?
US flags
US government IT contracts set to be centralized in new Trump order
An abstract image of digital security.
Fake file converters are stealing info, pushing ransomware, FBI warns
Latest in News
Zendesk Relate 2025
Zendesk Relate 2025 - everything you need to know as the event unfolds
Disney Plus logo with popcorn
You can finally tell Disney+ to stop bugging you about that terrible Marvel show you regret starting
Google Gemini AI
Gemini can now see your screen and judge your tabs
Girl wearing Meta Quest 3 headset interacting with a jungle playset
Latest Meta Quest 3 software beta teases a major design overhaul and VR screen sharing – and I need these updates now
Philips Hue
Philips Hue might be working on a video doorbell, and according to a new report, we just got our first look at it
Microsoft
"Another pair of eyes" - Microsoft launches all-new Security Copilot Agents to give security teams the upper hand