After Intel, it’s the turn of AMD processors to be affected by a new security flaw called Inception. As with Downfall, this vulnerability can lead to the theft of user data.
Inception, the flaw affecting AMD Zen 3 and Zen 4 processors!
The flaw was discovered by the Swiss Federal Institute of Technology in Zurich. According to AMD, which has already communicated on this issue, no exploit has yet been developed for it outside the research environment… At least, not to AMD’s knowledge, and since they’re the first to know, they must also be the first to know. You can imagine…
The result is a speculative side-channel attack. This is based on the way recent processors operate, exploiting speculative execution. The attacker then traps the CPU in a recursive function, injecting instructions into the prediction pipeline , leading to a data leak. However, data recovery rates are not very high. In fact, we’re talking about bytes per second.
Even so, slow as this recovery may be, it’s enough to steal security keys and the like. It’s all the more dangerous in that it affects all AMD processors currently in use, from the simple Ryzen to the Threadripper and the pros. The same applies to the embedded sector.
Finally, we learn that AMD is planning to roll out microcode and provide a new AGESA to OEMs, OEDs and motherboard manufacturers. It’s up to you to update your hardware, especially as the impact on performance is expected to be virtually nil. The same applies to anti-malware. This attack can only be carried out if the attacker already has a certain level of privileges on the machine. This level can be obtained via malware, for example.

