
Intel has confirmed that a recent leak of the source code for the UEFI BIOS of Alder Lake CPUs is authentic.
Alder Lake is the name of the 12th generation Intel Core processors , which were released in November 2021. On Friday, a Twitter user by the name “ freak ” posted links to the source code for the UEFI firmware of Intel Alder Lake CPUs , which he claims was leaked from 4chan .
The link led to a GitHub repository named “ICE_TEA_BIOS” uploaded by a user named “LCFCASD.” This repository contained what was described as “BIOS Code from project C970.”
See also: Linux Kernel 5.19.12: Bug can damage displays on Intel-based laptops

A total of 5.97 GB of files were exposed , which include source code, private keys, change logs, and compilation tools, with the most recent timestamp on the files being 9/30/22.
According to BleepingComputer's sources, the source code was developed by Insyde Software Corp, a UEFI system firmware development company.
The source code also appears to contain numerous references to Lenovo, including code for integrations with “Lenovo String Service”, “Lenovo Secure Suite” and “Lenovo Cloud Service”.
It is currently unclear how the source code was stolen and leaked, but Intel has confirmed to Tom's Hardware that the source code is authentic and is "proprietary UEFI code.".
“Our UEFI code appears to have been leaked by a third party. We do not believe this exposes any new vulnerabilities as we do not rely on information obfuscation as a security measure. This code is covered by the bug bounty program as part of the Project Circuit Breaker campaign and we encourage any researchers who can identify potential vulnerabilities to bring them to our attention through that program. We are reaching out to both customers and the security research community to keep them informed of this situation,” an Intel spokesperson said.
See also: LofyGang hackers created a credential theft operation
Intel source code leak: Concern in the research community
Intel has tried to convince the public that the source code leak poses little risk, but security researchers are concerned that the content could make it easier to find vulnerabilities in the code.
“Insyde's solution can help security researchers, bug hunters (and attackers) find the vulnerability and easily understand the result of reverse engineering, which increases the long-term high risk for users.“.
Positive Technologies researcher Mark Ermolov also warned that the leak included a private encryption key called KeyManifest, a private key used to secure Intel's Boot Guard platform.
See also: Toyota hack: Thousands of owners' information exposed
While it is unclear whether the leaked private key is used in production, if it is, cybercriminals could potentially use it to modify the boot policy in Intel firmware and bypass hardware security.
We are not yet aware of any ransom attempts, but Intel or affected parties may not have made these attempts public.
Recent hacks have targeted external suppliers to indirectly steal information from semiconductor, and this attack could follow that model.
Source: www.bleepingcomputer.com
