New DDRop Attack Breaks Intel TDX and AMD SEV-SNP Confidential Computing — SkimNews

Get the Tech newsletter
Daily tech — startups, AI labs, chips, the launches that shape the next decade. Free.
- DDRop drops writes via a $159 interposer board fitted between a processor and DDR5 memory module, exploiting the missing 'freshness' guarantee in scalable memory encryption so processors read old encrypted data as current.
- Intel TDX falls to full VM takeover: dropping page-table setup writes let attackers map their own VM onto any physical address, read victim memory, toggle debug mode, and forge attestation — Intel's optional cryptographic-integrity mode blocks the first two but not attestation forgery.
- AMD SEV-SNP sees a narrower result: dropping writes during page relocation lets researchers copy one victim page's contents into another, while debug-mode and attestation attacks are Intel-specific.
- AMD and Intel both told researchers the attacks fall outside their threat models because they require physical access; Intel declined to assign CVEs and said the research area is 'out of scope, but not out of mind.'
- Researchers from KU Leuven, ETH Zurich, Durham University, and Google will present DDRop at ACM CCS 2026 in November and are releasing interposer designs, controller firmware, and attack code on GitHub, with AMD's bulletin due September 14.
- NVIDIA's confidential-computing GPUs are out of reach because their memory sits inside the chip package where an interposer cannot fit; the researchers did not test Arm CCA and said it may be affected.
Why it matters: Cloud providers like AWS, Microsoft Azure, and Google Cloud rely on Intel TDX and AMD SEV-SNP to sell confidential-computing services that promise customer data stays private even from the provider — DDRop shows that promise can be undermined for roughly $159 and one brief physical visit, and both vendors have declined to issue patches or CVEs.
Ask SkimNews




