Gadget Bridge
HomeNewsAMD ‘Zenbleed’ bug is enabling hackers to steal data from Ryzen CPUs

AMD ‘Zenbleed’ bug is enabling hackers to steal data from Ryzen CPUs

A new vulnerability known as Zenbleed is discovered in AMD CPUs.

With the latest technological advancements in the modern world, cybercrime is on the rise as well. People are becoming more and more dependent on technology for their daily activities. In recent years researchers have found a ton of security bugs and loopholes in the processor. In 2018, the Spectre and Meltdown CPU exploits were presented in the world. Now recently, on July 24, 2023, another exploit was publicly disclosed. It was first reported in May and is specific to AMD processors built on Zen 2 architecture. The bug is named ‘Zenbleed’. 

Read Also: BenQ Launches State of the art 4LED 4K Smart Projector W4000i To Deliver Immersive, Theatre-Like Movie Experience at Home 

In This Article

- Advertisement -

What is ‘Zenbleed’

Zenbleed is a new bug discovered by Google security researcher Travis Ormandy. It impacts AMD Zen 2 CPUs and it could steal sensitive data such as passwords and encryption keys at a rate of 30kb/s. AMD ‘Zenbleed’ bug can be caused by improper handling of instruction called “vzeroupper”. The vulnerability occurs during speculative execution, a common performance-enhancing technique used in modern processors. 

Google security researcher Travis Ormandy said that The bug works like this, first of all, you need to trigger something called the XMM Register Merge Optimization2, followed by a register rename and a mispredicted vzeroupper. This all has to happen within a precise window to work. We now know that basic operations like strlen, memcpy and strcmp will use the vector registers – so we can effectively spy on those operations happening anywhere on the system. This works because the register file is shared by everything on the same physical core. In fact, two hyper threads even share the same physical register file. 

The most worrying thing about the AMD Zenbleed bug is that the attacks can be carried out remotely. The attack can be carried through JavaScript on a website. 

- Advertisement -

How to deal with AMD Zenbleed?

A microcode patch for second-generation Epyc-7002 processors has been released by AMD. However, updates for other processors are not arriving until October or December. The performance after the update will depend on workload and system configuration. Although it is recommended to install AMD’s microcode update for every user. 

Read Also: Top 10 apps to download first on Samsung Galaxy Z Flip 5

Conclusion

The increased hacking incidents happening around us have forced people to become more and more aware of their devices and appliances. People are becoming more involved in setting a control bit to disable some of the functionality that prevents exploitation. The microcode update can impact the system’s performance but it is better to be safe than to be sorry. 

For the latest gadget and tech news, and gadget reviews, follow us on TwitterFacebook and Instagram. For newest tech & gadget videos subscribe to our YouTube Channel. You can also stay up to date using the Gadget Bridge Android App. You can find the latest car and bike news here.

Support Us

We are a humble media site trying to survive! As you know we are not placing any article, even the feature stories behind any paywall or subscription model. Help us stay afloat, support with whatever you can!

Support us
- Advertisement -
Gadget Bridge Bureau
Gadget Bridge Bureauhttp://gadgetbridge.com
Team Gadget Bridge is your ultimate source for all things electronic. Our comprehensive coverage spans the latest gadgets, breaking tech news, insightful how-to guides, the business behind technology, enterprise-level tech solutions, and emerging careers in the tech industry. We're committed to bringing you the most up-to-date and in-depth technology news from around the globe, with the aim of being your go-to destination for tech insights and updates.
- Advertisement -

LEAVE A REPLY

Please enter your comment!
Please enter your name here

- Advertisement -

Latest From Gadget Bridge

Volleyball Legends Codes (September 2025)

If you’re a fan of the anime series Haikyuu, you cannot miss its Roblox adaptation. Previously known as...
- Advertisement -

Latest Reviews

Lava Blaze Dragon 5G Review: The budget smartphone that breathes fire

Lava’s newest entry-level offering is priced at Rs 10,000. At this price point, it faces tough competition from...
- Advertisement -

Tech How To

How to create a calling card in Google Contacts

Google's new facelift for its Phone app hasn’t gone down well with its users. However, the Contacts app...
- Advertisement -