Skip to content
July 24, 2026
  • Linkedin
  • Twitter
  • Facebook
  • Youtube

Daily CyberSecurity

Zero-hour alerts. Unmatched analysis.

Primary Menu
  • Home
  • CVE Data
    • CVE Watchtower
    • Top Exploited CVEs
    • CVE Stats by Vendor
    • Q2 2026 Report
  • Cyber Criminals
  • Data Leak
  • Linux
  • Malware
  • Vulnerability
  • Submit Press Release
  • Weekly Recap
Light/Dark Button
  • Home
  • News
  • Technology
  • 22-year-old Google cybersecurity researcher tell how to find CPU bugs
  • Technology

22-year-old Google cybersecurity researcher tell how to find CPU bugs

Do Son January 18, 2018 5 minutes read
Jann Horn
Add Daily CyberSecurity as a preferred source on Google

On January 17, Bloomberg published an article on Wednesday, introduced the first report of Intel’s major chip loopholes on Google genius researcher Jann Horn. Horn gifted, childhood good at mathematics and physics, in high school, found the school computer network security issues, which made his teacher dumbfounded.

 

Jann Horn, Source: Stiftung Jugend forscht e. V.

 The article said Horn accidentally discovered the largest chip loophole in the history of the Intel processor manual, which is inseparable from his firm will and extraordinary talent.

The following is a summary of the article:

In 2013, a teenager named Horn participated in a reception hosted by German Chancellor Angela Merkel in Berlin. At that time, he and another 64 German teenagers performed well in a government-run competition. The competition is designed to encourage students to engage in scientific research.

Horn really went on the path of scientific research. Last summer, as a 22-year-old cybersecurity researcher, he first reported the biggest chip loophole found in history. Now, the industry still did not get rid of the impact of his discovery. From now on, the processor will use a different design. The discovery made him a celebrity, even though he himself did not. This can be seen at a meeting held last week in Zurich: At the time, he was warmly received by the organizers of the conference and received many questions.

Interviews with Horn and those who know him show that firm will and extraordinary talent helped Horn find the loophole that has existed for more than a decade but has never been noticed. The vulnerability could result in the attack on most PCs, the Internet, and smartphones.

Several months after Horn unbelievably discovered the loophole, other researchers discovered. “We have a few teams and we have a clue as to where to start. He is a little startled from scratch,” says Daniel Gruss, a member of the Austrian Graz Technical University team, who later uncovered what he now knows Meltdown and Specter vulnerabilities.

When Horn began reading the thousands of pages of Intel processor manuals at the end of April last year, he did not try to find a major loophole in the world’s computer chips. He said he was just trying to make sure that the computer hardware was able to deal with a particularly large amount of digital arithmetic code that he had written.

However, Horn works on the Google Project Zero team. The elite department is made up of top talent looking for “zero-day” and unexpected design vulnerabilities that could invade computer systems by hackers.

So, he began to carefully study how the chip performs speculative execution. Speculative execution is a speed-boosting technique that allows the processor to guess a portion of the code to be executed in the next step, perform these steps in advance, and grab the data it needs. Horn said Intel’s manual states that if the processor guessed wrongly, then the data fetched by mistake was still stored in the chip cache.

Horn realizes that once this is done, the message may be used by savvy hackers. “At that time, I realized that we were using code patterns that could reveal confidential data,” Horn said in an email. “I was aware at the very least that in theory, it might not only affect what we were writing Code snippet. ”

So he started a further investigation what he called the “gradual process,” and eventually found the loopholes. Horn said he had known about other researchers at the time, including research from the team at the Graz Technical University. The theme of these studies is that a slight difference in the amount of time it takes for the processor to retrieve information may give hackers access to where the information is stored.

Horn discussed the issue with Felix Wilhelm, another young researcher at Google in Zurich. William provided Horn with a similar study he and other researchers had done, which led to Horn’s “debauchery.” The technology being tested by William and other researchers may be reverse-processed, forcing the processor to run new speculative execution routines that are not usually attempted. This fools the chip to retrieve specific data that may be available to hackers.

After accidentally discovering the chip attack, Horn said he consulted with Robert Swiecki, an old Google colleague. Horn had borrowed from Swiecki’s computer and tested some of his thoughts. Swiecki provided him with advice on how best to notify Intel, ARM, and AMD about the vulnerability.

On June 1 last year, Horn told Intel, ARM, AMD informed of this loophole.

Wolfgang Reinfeldt, a Horn computer science teacher at Caecilienschule High School in Oldenburg, Germany, was not surprised at Horn’s success. “In my mind, Horn is brilliant,” he said. Horn had discovered the security problems in the school’s computer network, making Rheinfelter have to admit that made him dumbfounded.

Horn is good in mathematics and physics in his youth. To attend Merkel’s reception in 2013, Horn and an alumnus conceived a way to control the movement of double pendulums. A double pendulum is a well-known math puzzle. The two wrote software that used sensors to predict the movement of double pendulums and used magnets to correct unintended movements. The key to solving this problem is to move the double pendulum regularly. The two eventually finished fifth in the competition and were invited to attend the Merkel reception in Berlin, which initially showed Horn’s personal abilities.

Now, Horn has become a star, at least in the cybersecurity circle like this. On January 11, just one week after the “meltdown” and “ghost” loopholes were announced, a conference on cybersecurity was held in Zurich. While Horn presented his discovery of “melted” and “ghostly” holes in the packed auditorium, his fellow undergraduate researcher gave him a thunderous applause.

Source: Bloomberg

Get Zero-Hour Vulnerability Alerts

Critical CVEs, CVSS scores, and PoC updates — straight to your inbox every week.


We respect your inbox. Unsubscribe anytime.

Related coverage

  • YouTube Tests AI Overviews for Video Summaries with Gemini
  • Space Race: SpaceX Lands $2 Billion Contract for Trump’s “Golden Dome” Missile Defense
  • From Desktop to Mobile: Thunderbird Expands its Reach with Upcoming iOS App
  • The fish tank became a medium for hacker attacks
  • Reddit has finally changed in the first major redesign
Track all actively exploited CVEs →

Support Our Threat Intelligence

If you find our CVE report and cybersecurity news helpful, consider supporting our work.

Buy Me a Coffee Logo Buy Me a Coffee PayPal
Crypto QR Code
USDT (TRC20):
TN8BdV8cp4T1Cd28gK9qTAnZknzzuwyUtm
USDT (ERC20):
0x3725e1a7d3bc5765499fa6aaafe307fabcd75bce

Share this article:

Facebook Post LinkedIn Telegram
Written by
@DdoS · Security Researcher

Do Son

Do Son is the Founder and Editor of SecurityOnline.info. Working in cybersecurity since 2013, he reports on vulnerabilities, malware, and emerging threats, providing timely analysis to help organizations and individuals stay ahead of evolving risks.

Tags: Jann Horn

Search

Translation

CVE WATCHTOWER
🚨

Receive alerts for vulnerabilities being exploited in the wild.

⚡

Get notified instantly when a Proof of Concept (PoC) exploit is published.

🔍

Access critical info on vulnerabilities even when marked as "RESERVED".

🧠

Insights powered by decades of expertise and global intelligence sources.

🎯

Customize alerts with up to 10 keywords for your specific tech stack.

📊

Export the raw CVE database for SIEM integration and reporting.

Upgrade Package

🚨 Active Exploits in the Wild

  • CVE-2026-16232CVSS 9.1
    An authentication bypass vulnerability in the Check Point SmartConsole login process allows an unauthenticated remote attacker to obtain...
    CISA KEV📅 Added to KEV: Jul 22, 2026
  • CVE-2026-50522CVSS 9.8
    Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.
    Admin intelCISA KEV📅 Added to KEV: Jul 22, 2026📅 Updated: Jul 21, 2026
  • CVE-2026-63030CVSS 9.8
    WordPress 6.9.x before 6.9.5 and 7.0.x before 7.0.2 is affected by a REST API batch endpoint route confusion...
    Admin intelCISA KEV📅 Added to KEV: Jul 21, 2026📅 Updated: Jul 21, 2026
  • CVE-2026-60137CVSS 5.9
    WordPress 6.8.x before 6.8.6, 6.9.x before 6.9.5, and 7.0.x before 7.0.2 does not properly sanitise the author__not_in parameter...
    Admin intelCISA KEV📅 Added to KEV: Jul 21, 2026📅 Updated: Jul 21, 2026
  • CVE-2026-0770CVSS 9.8
    Langflow exec_globals Inclusion of Functionality from Untrusted Control Sphere Remote Code Execution Vulnerability. This vulnerability allows remote attackers...
    CISA KEV📅 Added to KEV: Jul 21, 2026
  • CVE-2021-27137CVSS 8.1
    An issue was discovered in router/upnp/src/ssdp.c in DD-WRT before 45724. An unsafe strcpy in the UPnP handling functionality...
    CISA KEV📅 Added to KEV: Jul 21, 2026
  • CVE-2026-6875CVSS 9.5
    ServiceNow has addressed a remote code execution vulnerability that was identified in the ServiceNow AI platform. This vulnerability...
    Admin intel📅 Updated: Jul 18, 2026
  • CVE-2026-39808CVSS 9.8
    A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox...
    CISA KEV📅 Added to KEV: Jul 16, 2026
Powered by CVE Watchtower

🔴 Live Critical Threats

  • CVE-2026-61884CVSS 9.8
    The web management interface of Tycon Systems TPDIN-Monitor-WEB2  does not perform server-side validation...
  • CVE-2026-62379CVSS 9.8
    ## Summary A pre-authentication remote code execution vulnerability affects OpenAM. The remote...
  • CVE-2026-62263
    ### Summary The GHSA-6c99-87fr-6q7r fix wrapped WebAuthn authenticator deserialization in an `ObjectInputFilter`...
  • CVE-2026-62835CVSS 9.3
    Improper authorization in Azure Portal allows an unauthorized attacker to disclose information...
  • CVE-2026-48021CVSS 9.1
    In epa4all, prior to version 2026-05-20, an attacker who can intercept the...
  • CVE-2026-59940CVSS 9.8
    ## Summary A type confusion issue in `seroval.fromJSON()` allowed attacker-controlled JSON input...
  • CVE-2026-58630CVSS 10.0
    Improper access control in Azure App Service allows an unauthorized attacker to...
  • CVE-2026-57106CVSS 10.0
    Server-side request forgery (ssrf) in Data Quality allows an unauthorized attacker to...
  • CVE-2026-56163CVSS 10.0
    Missing authentication for critical function in Microsoft Azure Kubernetes Service allows an...
  • CVE-2026-15704CVSS 9.8
    In Eclipse BaSyx Go Components versions up to and including 1.0.0, ABAC-enabled...
Powered by CVE WATCHTOWER

Our Websites
  • Penetration Testing Tools
  • The Daily Information Technology
  • Top Exploited CVEs
  • Daily CyberSecurity

    • About SecurityOnline.info
    • Advertise with us
    • Announcement
    • Contact
    • Contributor Register
    • Login
    • Disclaimer
    • DCMA
    • Privacy Policy
    • About SecurityOnline.info
    • Advertise on SecurityOnline.info
    • Contact Us

    When you purchase through links on our site, we may earn an affiliate commission. Here’s how it works

    • CVE Watchtower
    • CVE Statistics by Vendor 2026
    • Q2 2026 Report
    • Top Exploited CVEs
    • Linkedin
    • Twitter
    • Facebook
    • Youtube
    © 2017 - 2026 Daily CyberSecurity. All Rights Reserved.