In plain language
What this advisory means
Google Cloud found serious security weaknesses in Intel's Trust Domain Extensions (TDX) firmware, a technology used to protect Confidential Virtual Machines (VMs). These flaws could let a powerful attacker with control over the host system bypass security checks, view restricted system settings, or read private memory from these protected VMs. Google has already updated their servers’ firmware to fix these issues, so most customers don't need to take action unless specifically instructed.
Technical explanation
How the issue affects the environment
Multiple vulnerabilities were discovered in Intel® TDX firmware affecting its attestation mechanisms and memory protections for Confidential VM instances that rely on TDX. A privileged adversary on the host could exploit flaws to bypass attestation checks, gain access to restricted CPU registers, or decrypt guest memory that is normally protected under TDX. These issues threaten the confidentiality and integrity guarantees of Confidential VMs running on Intel-based infrastructure. Google has proactively deployed firmware upgrades across its server fleet to mitigate these risks, applying patches from Intel's PSIRT advisories addressing CVE identifiers including CVE-2025-31938, CVE-2025-35973, CVE-2026-20898, and others.
Operational impact
Why teams should care
These vulnerabilities could critically undermine the security assurances of Confidential VMs on Google Cloud, risking sensitive customer data exposure and system integrity if exploited by a privileged host adversary. However, Google’s proactive firmware updates reduce the risk to customers by securing the underlying infrastructure without requiring customer action. Customers who operate Confidential VM workloads on Intel TDX platforms benefit from improved trustworthiness and compliance assurance. No disruption or immediate mitigation steps are expected for most customers due to Google's transparent handling.
Immediate action
Google has proactively applied firmware upgrades to its server fleet hosting Confidential VM instances to mitigate these vulnerabilities. Customers who have not received separate guidance to upgrade do not need to take action.
Affected and fixed releases
Temporary risk reduction
The official advisory does not specify any customer-side workarounds. The mitigation is applied at the infrastructure level by Google.
Evidence and validation checklist
- Official Google Cloud Security Bulletin GCP-2026-053
- Intel PSIRT technical advisories referenced by Google
- CVEs listed are Intel TDX firmware vulnerabilities
- Google Kubernetes Engine Confidential VM infrastructure updated
Authoritative reference
Google Cloud Security Bulletins
QCS detected and normalized this record from the official source. Vendor guidance remains authoritative.
