Plundervolt Attack Exploits Chip Voltage to Breach Secure Enclaves

A new exploit called Plundervolt bypasses software security by physically manipulating the voltage supplied to Intel chips, allowing attackers to extract data from protected secure enclaves.

A new exploit called Plundervolt bypasses traditional software security by using physical means to compromise a chip's defenses. By manipulating the exact amount of electricity fed to an Intel processor, an attacker tricks the chip into revealing its innermost secrets. While not as widespread as Meltdown or Spectre, this unique vulnerability forces the tech industry to rethink how processors are designed and secured.

Modern chips carefully manage their power intake to avoid draining batteries or generating excess heat, and they feature secure enclaves like Intel's SGX to protect sensitive cryptographic processes. Researchers discovered that anyone with operating system control accesses hidden Model-Specific Registers that dictate chip voltage. By tweaking these settings, an attacker causes intentional malfunctions that bypass external security protections because the entire process happens internally.

The Plundervolt attack slightly alters the voltage going to the chip at the precise moment the secure enclave executes a critical task. This carefully timed drop induces predictable faults inside SGX, allowing attackers to exploit these controlled failures and extract secure data.

Read More at the original source →