Hardware backdoors in some x86 CPUs
Project:rosenbridge is a research effort led by Christopher Domas that has uncovered a hardware backdoor in certain x86 CPUs, specifically VIA C3 processors. This backdoor, embedded deeply within the CPU alongside the main x86 core, allows userland code to bypass processor protections and freely read and write ring 0 (kernel) data.
The backdoor is typically disabled but has been observed to be enabled by default on some systems. It is activated through a model-specific-register control bit and toggled with a launch-instruction, allowing a hidden CPU core to execute commands that bypass memory protections and privilege checks. This backdoor is entirely distinct from other known coprocessors in x86 CPUs and is thought to only affect VIA C3 CPUs, which are marketed towards industrial automation, point-of-sale, ATM, healthcare hardware, as well as consumer desktop and laptop computers.
The research from project:rosenbridge provides tools to check if a processor is affected, close the backdoor if present, and offers insights into how such vulnerabilities can arise in increasingly complex processors.
Written by urgent.news from Hacker News's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.
Also reported by 1 other outlet
- Hardware backdoors in some x86 CPUs github.com