Executive brief
Intel AI Playground, a tool for running artificial intelligence models locally, contains a security flaw that could allow an attacker to gain higher-level system permissions. To exploit this, an attacker would need local access to the computer and would need to trick a legitimate user into performing a specific action. If successful, the attacker could gain full control over the affected system, potentially leading to data theft or service disruption.
Technical details
An uncontrolled search path vulnerability (CWE-427) exists in Intel AI Playground software versions prior to 3.0.0 alpha. The flaw occurs within Ring 3 (User Applications) and can be exploited by an unprivileged, authenticated local adversary. Exploitation requires a high-complexity attack involving specific environmental preconditions and active user interaction (UI:A). If successful, the attacker can achieve an escalation of privilege, gaining high confidentiality, integrity, and availability impact on the local system. Intel has released version 3.0.0 alpha to mitigate this issue.
Affected products
- Intel AI Playground before 3.0.0 alpha
Timeline
- 2026-05-12: disclosed
- 2026-05-12: advisory
- 2026-05-12: patched: Version 3.0.0 alpha released