Skip to main content

Intel Alder Lake BIOS source code was leaked — should you be worried?

It’s official — the source code for the Intel Alder Lake BIOS was leaked, and Intel has confirmed it. A total of 6GB of code used for building the BIOS/UEFI source code is now out in the wild, having been posted on GitHub and 4chan.

Intel doesn’t seem too concerned, but security researchers are now hard at work trying to see if this can be used in a malicious way. If you own an Alder Lake CPU, should you be worried?

I can't believe: NDA-ed MSRs, for the newest CPU, what a good day… pic.twitter.com/bNitVJlkkL

— Mark Ermolov (@_markel___) October 8, 2022

News of the leak broke out a couple of days ago when the code was found in a public GitHub repository, as well as shared on 4chan. The 6GB file contains some of the tools and code that Intel has used to build the BIOS/UEFI in its Alder Lake CPUs. Seeing as these are some of the best processors out currently, this could potentially put a lot of Intel’s customers at risk.

The BIOS/UEFI source code is responsible for initializing the hardware even before the operating system has the chance to load. As such, it’s responsible for establishing secure connections to important mechanisms within the computer, such as the Trusted Platform Module (TPM). The BIOS plays an important role in any computer, so it’s certainly not good that the source code for it could now be in the hands of nefarious threat actors.

Initially, it was uncertain whether the leaked file was the real deal, but Intel itself has now confirmed that to be the case. In a statement issued to Tom’s Hardware, Intel said:

“Our proprietary UEFI code appears to have been leaked by a third party. We do not believe this exposes any new security vulnerabilities as we do not rely on obfuscation of information as a security measure. This code is covered under our bug bounty program within the Project Circuit Breaker campaign, and we encourage any researchers who may identify potential vulnerabilities to bring them to our attention through this program. We are reaching out to both customers and the security research community to keep them informed of this situation.”

Intel’s statement implies that the most sensitive data had already been scrubbed from the source code before it was released to external partners. The source code contains many references to Lenovo, including “Lenovo String Service,” “Lenovo Cloud Service,” and “Lenovo Secure Suite.” Bleeping Computer notes that all of the code was developed by Insyde Software Corp.

An Intel Alder Lake Core i5-12600K CPU and its packaging.
Jacob Roach / Digital Trends

While this leak sounds pretty bad, Intel doesn’t seem to be overly concerned — although it’s good that it refers everyone to its bug bounty program. Many security researchers are already looking for cracks in the code, and some of the findings are less optimistic.

Hardware security firm Hardened Vault told Bleeping Computer: “The attacker/bug hunter can hugely benefit from the leaks even if leaked [manufacturer] implementation is only partially used in the production. The Insyde’s solution can help the security researchers, bug hunters, (and the attackers) find the vulnerability and understand the result of reverse engineering easily, which adds up to the long-term high risk to the users.”

Seeing as a KeyManifest private encryption key was found in the leak, it’s possible that hackers could use it to bypass Intel’s hardware security. Even so, it’s still a fairly long shot, so you probably don’t have to be too worried.

In any case, it’s worth it to keep yourself safe with some antivirus software to ensure that no attackers can access your computer, and subsequently, the BIOS.

Editors' Recommendations

Monica J. White
Monica is a UK-based freelance writer and self-proclaimed geek. A firm believer in the "PC building is just like expensive…
Intel may have accidentally leaked the release date for Windows 12
Someone typing on the Surface Laptop Studio 2's touchscreen.

Did we just get a confirmation about the release time frame for Windows 12 -- and from Intel, of all sources? It seems that way. Intel spoke about its predictions for 2024, indicating that it expects 2024 to be a good year for client processors. That's huge for Intel because the next generation of its top processors, Meteor Lake, is set to come out in 2024. However, if Intel is right, it might be a big year for Microsoft, too.

The information comes from a transcript of the Citi 2023 Global Technology Conference. Most of it wasn't too exciting -- fireside chats aren't often that interesting to the masses -- but there's a little comment in there that piqued our interest.

Read more
Intel’s Raptor Lake refresh prices have leaked, and hikes are on the way
An Intel processor over a dark blue background.

We're most likely just a couple of weeks away from the release date for the Intel Raptor Lake refresh, and while Intel itself hasn't said much about it, interesting tidbits of information leak out pretty frequently. Today, we got a good look at what might be the pricing of almost the entire lineup. And it looks like price increases are coming, however minor they may be.

We expected that a price hike was likely for the Raptor Lake refresh, and that's exactly what seems to be happening. As per a tip sent to VideoCardz, the majority of the 14th-Gen lineup appeared briefly at a Canadian retailer known as Canada Computers. While the CPUs weren't listed, they could be found by searching for the product names, and that gives an idea of what to expect. Keep in mind that these prices are in Canadian dollars.

Read more
Intel Meteor Lake is coming to desktop, but there’s a big catch
Intel announcing the Meteor Lake release date on Intel Innovation.

It's been a real roller coaster ride with Intel Meteor Lake. First, it was coming to desktops, then it wasn't, then it was, and now ... it isn't, but it is. If you're as confused as we are, don't worry -- Intel has set things straight and we now know that Meteor Lake chips will be available in desktops, but they won't become some of the best processors for desktop PCs, all because they're not socketed.

Intel spoke about the future of its 14th-Gen Meteor Lake chips in a statement made to ComputerBase, revealing that, yes, Intel Meteor Lake will come to desktop PCs, but only all-in-one (AIO) computers like the Intel NUC or small form-factor PCs. It won't be available in socketed form, which means that you won't be able to install it in a future LGA1851 motherboard. In short, Meteor Lake chips are laptop CPUs, through and through.

Read more