Google researchers identify hole in Intel TDX

Intel has worked with Google to figure out how to harden the TDX module in Xeon chips to boost the security of virtual machines

Cliff Saran

By

Published: 26 Apr 2023 11:00

Google’s Project Zero and cloud security teams’ nine-month assessment of the security of the Intel Trust Domain Extension (TDX) has identified a number of areas it needs to improve, but overall, the company gave the new technology, which will be included in the fourth generation of Intel’s Xeon Scalable processor, the thumbs-up.

The TDX module is a feature in the next generation of Xeon processors that provides hardware-isolated virtual machines (VM), known as Trust Domains (TD). These can be used to isolate sensitive resources, such as virtualised physical memory, from the host operating system on which the VM runs.

The research, conducted in collaboration with Intel, looked at how to prevent confidential computing technology from threats today and into the future.

Intel said the research was used to identify if there were obvious defects in TDX and test if it works as expected to ensure the technology could be deployed by both cloud customers and providers. The researchers also wanted to have a better understanding of the expected threat model for TDX, and identify limitations in the design and implementation that would better inform Google’s deployment decisions.

The security review assessed arbitrary code execution in a privileged security context; cryptographic weaknesses; temporary and permanent denial of service and weaknesses in debug or deployment facilities. Intel has also opened the source code to the components the team reviewed so that further research can be performed in public. The source code available for public review includes the TDX Module and Seam Loader.

The report points out a serious implementation issue due to a bug in the Authenticated Code Module (ACM) responsible for initialising the TDX feature.

The researchers found that when the ACM moves between its secure and unsecured state, the bug allows untrusted code to execute in “privileged execution mode”, which has a high level of security. This bug can be exploited to compromise the integrity of the TDX feature and the security of any deployed VMs.

The defects and weaknesses identified during the review were fed back to Intel for remediation.

Nelly Porter, group product manager for Google Cloud, said: “As industry leaders in confidential computing, we make it our mission to thoroughly review the underlying technology, especially as we offer it to our customers. We are pleased at the level of security already baked into Intel TDX, as well as the collaboration between our teams that improves security outcomes for the entire industry.”

“We want to make it such that people don’t worry about the security and trustworthiness of their data,” said Anil Rao, vice-president and general manager of systems architecture and engineering in the office of the chief technology officer at Intel.

“Organisations use confidential computing to control their data and provide access to trusted parties in a manner that is verifiable, revocable and time-sensitive – we have an obligation to make sure the technology is secure. Our early effort with Google solidifies our commitment to perform thorough analysis to address all potential vulnerabilities.”

Read more on IT risk management

Read More
Anthony Antes

Latest

Festering Infections to Untreated Cancer: ICE Detainees Describe Medical Neglect Across US

An Albanian man’s pain grew so unbearable, he said, he pulled out his own tooth as he languished for months in a New Mexico immigration detention center. A Honduran mother of two said she was hospitalized for a heart problem after she was denied blood pressure medications while held in Florida. A Venezuelan man said

Focused on Work, Needed at Home: A Federal Caregiving Policy Might Help

(Candice Evers for WPLN and KFF Health News) Jill Woodrow reached a tipping point as a caregiver when her mom began struggling to communicate information about her latest doctor appointments. Woodrow’s mother, a uterine cancer survivor, was seeing specialists to get to the bottom of several new, concerning symptoms. “When she would try to tell

How digital platforms and policy shifts reshape GLP-1 affordability

🛡️ Just a quick check We’re checking your connection to prevent automated abuse

Baffling. Frustrating. Frightening. What It’s Like To Be Sued Over Medical Debt.

When Christine Wood received a $12,000 bill from Bristol Hospital, she thought it must be a mistake. It was more than she and her husband made in a month combined. “I’m freaking out,” said Wood, who lives in a 1,700-square-foot home in Terryville, a village just outside Bristol, Connecticut. “I don’t understand it.” Wood, 52

Newsletter

Don't miss

Festering Infections to Untreated Cancer: ICE Detainees Describe Medical Neglect Across US

An Albanian man’s pain grew so unbearable, he said, he pulled out his own tooth as he languished for months in a New Mexico immigration detention center. A Honduran mother of two said she was hospitalized for a heart problem after she was denied blood pressure medications while held in Florida. A Venezuelan man said

Focused on Work, Needed at Home: A Federal Caregiving Policy Might Help

(Candice Evers for WPLN and KFF Health News) Jill Woodrow reached a tipping point as a caregiver when her mom began struggling to communicate information about her latest doctor appointments. Woodrow’s mother, a uterine cancer survivor, was seeing specialists to get to the bottom of several new, concerning symptoms. “When she would try to tell

How digital platforms and policy shifts reshape GLP-1 affordability

🛡️ Just a quick check We’re checking your connection to prevent automated abuse

Baffling. Frustrating. Frightening. What It’s Like To Be Sued Over Medical Debt.

When Christine Wood received a $12,000 bill from Bristol Hospital, she thought it must be a mistake. It was more than she and her husband made in a month combined. “I’m freaking out,” said Wood, who lives in a 1,700-square-foot home in Terryville, a village just outside Bristol, Connecticut. “I don’t understand it.” Wood, 52

Former Angels Top Prospect Jordyn Adams, 26, Commits To SMU Football

The 2018 wide receiver recruiting class was spearheaded by top prospects Amon-Ra St. Brown and Ja’Marr Chase. Both elite talents lived up to the immense hype and have since become All-Pro receivers in the NFL. Lost in that group was the player who sat between Brown and Chase in the rankings — a once highly-touted

Jury acquits 2 business executives of bribing Navy admiral for government contract

A federal jury has acquitted two business executives of charges that they conspired to bribe a retired four-star U.S. Navy admiral, who is now serving a six-year prison sentence for his conviction on corruption charges By MICHAEL KUNZELMAN Associated Press WASHINGTON -- A federal jury has acquitted two business executives of charges that they conspired

US Business Leaders Optimistic About China Cooperation, Emphasize Importance of Chinese Market

© 2026 China Money Network. All Rights Reserved. Disclaimer: The views, opinions, forecasts, and statements made by our hosts and guests are the personal views of those respective individuals and may or may not be either endorsed or accepted by China Money Network Limited or the companies with which these individuals are employed.

Tesla’s Business Has Become Much More Diversified in Just the Past Five Years. Does That Make Its Stock a Better Buy Today?

Key Points Tesla's energy generation and storage segment generated 27% revenue growth last year. The company's non-automotive segments were able to help offset a double-digit decline in auto revenue in 2025. These 10 stocks could mint the next wave of millionaires › Tesla (NASDAQ: TSLA) is known for its electric vehicles (EVs), and while they