TechNewsReel
Live

Loongson CPUs Vulnerable to Cache Side-Channel Attacks, CISPA Finds

Security flaws in China's domestic processors could allow attackers to extract sensitive data via 'leaky' caches.

TechNewsReel Newsroom · August 13, 2026

Researchers from Germany's CISPA Helmholtz Center for Information Security have discovered critical cache side-channel vulnerabilities affecting processors manufactured by China's Loongson. The flaw allows attackers to extract sensitive data from the system by exploiting hardware leakage.

The vulnerability centers on "leaky" caches, specifically involving instruction and data-cache incoherence. According to the CISPA Rootsec group, this architectural weakness enables side-channel attacks, where an attacker can infer secret information by observing how the processor handles data in its cache. These findings are part of a broader study into architectural leakage affecting multiple platforms, including LoongArch, ARM, and RISC-V.

The Drive for Self-Reliance

Loongson is a central pillar of China's strategic push for semiconductor self-reliance. By developing domestic CPUs, Beijing aims to eliminate its dependence on Western x86 and ARM architectures. This transition is critical for China's national security and industrial autonomy, as the government seeks to insulate its critical infrastructure from potential foreign sanctions or supply chain disruptions.

Implications for Hardware Security

Side-channel attacks typically exploit shared hardware resources to infer secrets based on timing or power consumption. The discovery of these vulnerabilities undermines the security claims of China's domestic hardware ecosystem. This is particularly concerning for cloud computing environments, where multi-tenancy relies on the strict isolation of virtual machines. If the underlying CPU cache leaks information, the boundary between different users or the host system can be compromised, posing a significant risk to government and corporate data hosted on Loongson-based infrastructure.

Looking Ahead

While the core vulnerability has been confirmed, the industry now awaits a formal response and patching strategy from Loongson. The discovery highlights a recurring challenge in CPU design: the trade-off between performance optimization and absolute security. Observers will be watching to see if Loongson can implement hardware-level mitigations without sacrificing the efficiency of its domestic chips, and whether similar flaws exist in other emerging non-x86 architectures. The ability to secure these chips is paramount if China intends to deploy them in high-security environments where data isolation is non-negotiable.

Sources

Get a notification when a big story breaks. A few a day at most — no spam.