🟠 High  |  Source: GCP Compute Engine Security Bulletins


Intel has disclosed a new side-channel vulnerability (CVE-2024-45332) affecting several processor families including Cascade Lake, Ice Lake, Sapphire Rapids, and Emerald Rapids. Google has already patched all affected infrastructure within Google Cloud, meaning customers are protected without needing to take any action. No evidence of active exploitation has been reported.

Security Architect’s Take: No immediate action is required for workloads running on Google Cloud, as Google has already applied mitigations fleet-wide. However, architects running affected Intel processors in on-premises or hybrid environments should review Intel advisory INTEL-SA-01247 and apply relevant microcode or firmware updates independently.

Original advisory: GCP-2025-025