Junglewise Threat Intelligence

CVE-2025-35979: Intel Processors Information Disclosure in Microarchitectural Predictor State

CVE-2025-35979 · Severity: info · CVSS 6.8 · Published 2026-05-12

Technologies: Intel Core Ultra Processors Series 2, Intel Core Ultra Processors Series 3. Vendors: Intel.

Executive brief

A security vulnerability in certain Intel processors could allow a malicious user to access sensitive information from other users or virtual machines on the same system. This issue stems from how the processor predicts future instructions, which can inadvertently leave traces of private data in shared hardware components. While the attack is complex to execute, it could lead to the theft of passwords, encryption keys, or other confidential data. Intel has released microcode updates to address this issue, and users are advised to update their system firmware (BIOS).

Technical details

This vulnerability is a transient execution side-channel attack involving shared microarchitectural predictor states within VMX non-root (guest) operations. An unprivileged local attacker with authenticated access can exploit shared predictor states to influence transient execution and observe sensitive data across security boundaries (e.g., from a guest VM or another process). The attack is characterized by high complexity and requires specific architectural preconditions to be met. Intel has addressed this via microcode updates (INTEL-SA-01420) for affected Arrow Lake, Lunar Lake, and Panther Lake platforms.

Affected products

  • Intel Core Ultra 200S Series Processors (Arrow Lake)
  • Intel Core Ultra Processors Series 2 (Lunar Lake)
  • Intel Core Ultra Processors Series 3 (Panther Lake)

Timeline

  • 2026-05-12: disclosed
  • 2026-05-12: patched: Microcode updates released via INTEL-SA-01420

References

Related threats