ucode blobs are usually signed with strong crypto (RSA-2048 on Intel iirc), so unless the NSA doesn't get the keys or the raw transistor layouts of the CPU in order to look for bugs, no way to mess with the bytecode.

I'm paranoid enough to assume they have both the keys and the layout.

