Hardware backdoors found in some x86 CPUs - Rosenbridge documents a hidden execution layer

Security & Trust just now0Add to bookmarks

Hardware backdoors found in some x86 CPUs - Rosenbridge documents a hidden execution layer
Illustration : Léa Fontaine

A researcher has documented undisclosed execution capabilities in certain x86 processors—a hidden RISC core that runs below the OS and hypervisor with no visibility to security monitoring tools.

In plain terms: The Rosenbridge research (github.com/xoreaxeaxeax/rosenbridge, DEF CON 2018) documents hidden RISC cores inside certain x86 processors that can execute instructions with no visibility to the OS or hypervisor. An attacker with initial access could run code below kernel privilege rings—in a space that security monitoring tools cannot reach.

The research is not theoretical. The coprocessor is activated via a model-specific register (MSR) that enables a hidden execution mode. The MSR value is undocumented and undisclosed by the chip vendor. x86's long history of undocumented instructions makes this class of vulnerability structurally plausible beyond the specific silicon documented.

[Under the hood] CPU privilege rings (ring 0–3) are the foundation of OS security. A backdoor operating below ring 0 defeats kernel-level detection, hypervisor isolation, and most EDR tooling. Detection requires hardware-level attestation—not software scanning.

So what: As AI workloads concentrate on commodity x86 server fleets (including shared cloud infrastructure), hardware supply chain trust becomes a harder problem. This belongs in the threat model of any team running sensitive AI inference on shared or third-party hardware—especially across jurisdictions where CPU manufacturing provenance is opaque.

Resources, try it

Article produced by artificial intelligence, reviewed under human editorial control.

Our newsroom
Your Linux servers, as a desktop.
TermalOSSponsored
Ops, reimagined

Your Linux servers, as a desktop.

Agentless SSH monitoring, a full remote desktop and an AI ops copilot — no agents to install. Everything stays on your machine.

SSHMonitoringAI Ops
Get early access
Was this article helpful?

0 people liked this article

Like
S
Sofia AdlerSecurity & trust
🇬🇧 AI security, model safety, cyber.
Share:
Comments (0)

Sign in to join the discussion.

Be the first to comment.

Your Linux servers, as a desktop.
TermalOSSponsored
Ops, reimagined

Your Linux servers, as a desktop.

Agentless SSH monitoring, a full remote desktop and an AI ops copilot — no agents to install. Everything stays on your machine.

Get early access
Topics
Explore
Information