ON
← Back to feed
The security coprocessor in many CPUs is insecure
Germany🏛️ Politics11 days ago

The security coprocessor in many CPUs is insecure

Eine Sicherheitslücke wurde im Trusted Platform Module (TPM), einer Sicherheitskomponente in modernen CPUs von AMD und Intel, entdeckt. Die Lücken, CVE-2026-6726 und CVE-2026-6727, ermöglichen Angreifern, geheime Daten aus dem TPM zu lesen oder falsche kryptografische Schlüssel einzusetzen. Diese Schwachstellen sind besonders relevant für Unternehmen, da sie potenziell zum Einbrechen in Netzwerke führen können. Die Lücken erfordern lokalen Zugriff mit privilegierten Rechten, was sie für Privatanwender weniger bedrohlich macht. AMD und Intel haben Updates bereitgestellt, um die betroffenen CPUs zu schützen.

A critical security vulnerability has been identified in the firmware of the Trusted Platform Module (TPM) used in many processors from AMD and Intel. The flaw affects systems relying on the fTPM 2.0 reference code supplied by the Trusted Computing Group (TCG), which both companies incorporate into their BIOS versions. This component forms the root of trust for servers, desktop PCs, and notebooks, storing cryptographic keys essential for verifying system integrity and enabling features such as Windows BitLocker encryption. The vulnerabilities, designated as CVE-2026-6726 and CVE-2026-6727, have been rated highly severe with scores of 8.5 and 8.3 respectively under the Common Vulnerability Scoring System (CVSS). These flaws could allow attackers to manipulate the TPM, potentially compromising the entire system's security. However, exploiting these issues requires local access with elevated privileges, making them less of a concern for individual users than for corporate environments where devices might be more vulnerable to targeted attacks. CVE-2026-6727 involves a side-channel attack that exploits timing differences to extract secrets from the TPM. Attackers can use specially crafted software to send numerous commands to the coprocessor and measure the time taken for responses. By analyzing variations in response times, attackers can infer information about the cryptographic operations being performed, specifically filling blocks using the RSA-OAEP encryption method. Correct and incorrect fill values produce different response times, allowing attackers to deduce sensitive data. CVE-2026-6726 undermines the verification process of stored cryptographic keys. Under certain conditions, the TPM fails to invalidate discarded keys properly, allowing attackers to present a new forged key at the same address as a legitimate one. This enables deep manipulation of the system, potentially allowing unauthorized access and control over the device. AMD has confirmed that all desktop, notebook, and embedded processors based on the Zen architecture, including models ranging from Ryzen 1000 to Ryzen 9000 and Ryzen AI 400, are affected. For server models, AMD lists only the smaller desktop counterparts, Epyc 4004 and Epyc 4005, while excluding the multi-core variants under the 7000 and 9000 series designations. Intel has stated that its affected processors include desktop, notebook, and embedded models up to and including the Core Ultra 200 series. For server models, Intel lists processor lines up to the third-generation Xeon Scalable family (Ice Lake) released in 2021. Both AMD and Intel have already distributed updated firmware versions to manufacturers of desktop PCs, notebooks, and motherboards. Over the coming weeks and months, these manufacturers will provide corresponding BIOS updates. In addition, software patches are being developed for components such as the Debian library libtpms and various Windows versions. The discovery of these vulnerabilities highlights the importance of secure firmware implementation in hardware components that form the foundation of system trust. While the immediate risk to individual users is low due to the requirement for local privileged access, the potential impact on enterprise environments underscores the need for timely patching and robust security practices. Both AMD and Intel have taken proactive steps to mitigate the risks by distributing updated firmware and collaborating with operating system developers to ensure comprehensive protection against exploitation.

Go to the primary sources (6)

The official sources this coverage is built on. Read them directly to bypass framing.

1 reports

heise online logoheise onlineIndependentCenterFactual 95Objective 8511 days ago
The security coprocessor in many CPUs is insecure

Eine Sicherheitslücke wurde im Trusted Platform Module (TPM), einer Sicherheitskomponente in modernen CPUs von AMD und Intel, entdeckt. Die Lücken, CVE-2026-6726 und CVE-2026-6727, ermöglichen Angreifern, geheime Daten aus dem TPM zu lesen oder falsche kryptografische Schlüssel einzusetzen. Diese Schwachstellen sind besonders relevant für Unternehmen, da sie potenziell zum Einbrechen in Netzwerke führen können. Die Lücken erfordern lokalen Zugriff mit privilegierten Rechten, was sie für Privatanwender weniger bedrohlich macht. AMD und Intel haben Updates bereitgestellt, um die betroffenen CPUs zu schützen.

Bias read (Center): Der Artikel beschäftigt sich rein technisch mit Sicherheitslücken in Hardwarekomponenten und gibt keine politischen Bewertungen oder parteiengesponserten Meinungen再. Es wird keine Seite bevorzugt oder eine politische Agenda verfolgt. Die Berichterstattung bleibt sachlich und informativ.

Why factuality (95): The article accurately describes the security vulnerabilities in the Trusted Platform Module (TPM) used by AMD and Intel processors. It references specific CVE identifiers (CVE-2026-6726 and CVE-2026-6727) and explains the technical nature of the vulnerabilities as a side-channel attack. The informa

Why objectivity (85): The tone remains informative and explanatory, focusing on the technical aspects of the vulnerability without overt bias. However, there is a slight emphasis on the potential impact on corporate environments, which may subtly frame the issue as more critical than personal use.

How each side covered it

The same event, grouped by the political lean of the outlets covering it.

How each side covered it

Support independent, bias-aware news and unlock the social pulse, community voting, and every other Supporter feature.

Become a Supporter

Covered around the world

The same event as reported in other countries.

Covered around the world

Support independent, bias-aware news and unlock the social pulse, community voting, and every other Supporter feature.

Become a Supporter

Claims check

Key factual claims, and how many sources assert vs dispute each.

Claims check

Support independent, bias-aware news and unlock the social pulse, community voting, and every other Supporter feature.

Become a Supporter

Keep the news honest.

ObjectiveNews is reader-funded and ad-free — we show you the bias instead of hiding it. Support independent journalism for €4/month.

Become a Supporter

Related stories