Meltdown, Spectre Chip Flaws: Who's Affected

Advertisement
By Associated Press | Updated: 5 January 2018 13:05 IST
Highlights
  • Meltdown only affects Intel-based machines
  • Spectre affects Intel, AMD, ARM-based machines
  • Most software makers and OEMs have issued fixes already

Technology companies are scrambling to fix serious security flaws affecting computer processors built by Intel and other chipmakers and found in many of the world's personal computers and smartphones.

The two hardware bugs discovered can be exploited to allow the memory content of a computer to be leaked. Such a leak could potentially expose stored passwords and other sensitive data, including personal photos, emails and instant messages.

Researchers at Google's Project Zero and academic institutions including the Graz University of Technology in Austria discovered the problem last year and disclosed it Wednesday.

Advertisement

There's no evidence that bad actors have yet exploited the bugs, but companies from Microsoft to Mozilla said this week they have worked to patch up vulnerabilities to their operating systems and browsers to protect against one of the bugs. Researchers say the other is harder to fix and "will haunt us for quite some time."

Advertisement

Here's a look at what's affected, what's being done about it and whether you should worry.

Intel inside
Intel is at the centre of the problem because it supplies the processors used in many of the world's PCs. Researchers say one of the bugs, called Meltdown, affects nearly every processor it's made since the mid-1990s.

Advertisement

While security flaws are typically limited to a specific company or product, Intel says the problem is "not a bug or a flaw in Intel products" but rather a broader problem affecting processing techniques common to modern computing platforms.

Both the chipmaker and Google, which informed Intel about the vulnerability in June, said they were planning to disclose the issue next week when fixes will be available. Tech companies typically withhold details about security problems until fixes are available so that hackers wouldn't have a roadmap to exploit the flaws. But in this case, Intel was forced to disclose the problem Wednesday after British technology site The Register reported it, causing Intel's stock to fall.

Advertisement

Most of the immediate fixes will be limited to the Meltdown bug. The other, Spectre, is harder to fix, but also harder to exploit, making it less of an immediate threat to consumer devices.

Other chipmakers
While researchers say the Meltdown bug is limited to Intel processors, they have verified Spectre as a problem for Intel, Advanced Micro Devices and ARM processors. AMD chips are also common in PCs, while ARM chips are found in many smartphones and other internet-connected products, including cars and home appliances.

AMD said there is "near zero risk" to its own processors, either because its chips are designed differently, or security fixes for Microsoft Windows and other operating systems will take care of the problem. ARM Holdings said it's working with Intel, AMD and operating system vendors to address the problem. The ARM design is also used in Apple's mobile chips. Apple said late Thursday that all of its devices are affected, but it's already made fixes to help defend against Meltdown in laptops and phones and soon plans to release mitigations in the Safari browser to help defend against Spectre.

Securing the cloud
The bugs also affect cloud-computing services powering much of the internet. These services, offered by Amazon, Microsoft, Google, IBM and others, give smaller companies access to data centres, web hosting and other services they need to run their businesses. But these cloud services also use computers with the same types of problem chips.

Unauthorised access will be difficult to detect so cloud-computing providers need to act quickly to protect against these vulnerabilities, said Ryan Kalember, senior vice president of cybersecurity at Proofpoint. The good news, he said, is that major cloud providers have known about this for months and have had time to tackle the problem.

What to do next?
There are limits to what consumers can do now to protect their computers.

Advice from the US Computer Emergency Readiness Team's was grim. The federal organization says that "fully removing the vulnerability" requires replacing the hardware already embedded in millions of computing devices.

That's not to say nothing can be done.

Consumers can mitigate the underlying vulnerability by making sure they patch up their operating systems with the latest software upgrades. There are already Meltdown patches for Microsoft's Windows, Apple's macOS and Linux. Mozilla says it's also implementing a short-term mitigation that disables some capabilities of its Firefox browser. Google says Android devices are protected if they have the latest security updates.

"If you download the latest update from Microsoft, Apple, or Linux, then the problem is fixed for you and you don't have to worry," security researcher Rob Graham said in a blog post Thursday. "If you aren't up to date, then there's a lot of other nasties out there you should probably also be worrying about."

 

For the latest tech news and reviews, follow Gadgets 360 on X, Facebook, WhatsApp, Threads and Google News. For the latest videos on gadgets and tech, subscribe to our YouTube channel. If you want to know everything about top influencers, follow our in-house Who'sThat360 on Instagram and YouTube.

Advertisement

Related Stories

Popular Mobile Brands
  1. [Exclusive] Noise to Launch Flagship Master Series Over-Ear Headphones Soon
  2. Samsung Begins Rolling Out One UI 8 Update to the Galaxy S25 Series
  3. Vivo Y31 Series With 6,500mAh Battery Launched in India: See Price
  4. Nothing Announces Offers on Phones, Wearables During Flipkart Sale
  5. Flipkart Big Billion Days Sale: Discounts on Motorola Phones Announced
  6. Samsung Galaxy S25 FE With 50-Megapixel Camera Launched in India: See Price
  7. Check What's New for Your iPhone in Apple's Latest iOS 26 Update
  8. iOS 26 Released Alongside iPadOS 26, macOS Tahoe: Here's How to Download It
  9. Realme P3 Lite 5G With 6,000mAh Battery Launched in India at This Price
  10. iOS 26 Releases Today: Check Out the Notable Features
  1. The Witcher Season 4 Release Date Revealed: Know When and Where to Watch It Online
  2. iOS 26 Update Released Alongside iPadOS 26 and macOS Tahoe: Check Eligible Models, How to Download
  3. Scientists Propose Space Missions to Chase Down Interstellar Comets
  4. Iceland Plume Discovery Reveals Ancient Volcanic Funnels Across North Atlantic
  5. Huawei Watch Ultimate 2 Design Renders Leaked, Could Launch Soon
  6. Marvel's Wolverine Will Reportedly Launch in 2026; Insomniac's Venom Game in 'Active Development'
  7. US President Donald Trump Challenges Block on Removing US Fed’s Lisa Cook
  8. iPhone 17 Series Outpaces iPhone 16 in Demand While iPhone 17 Pro Max Tops Pre-Orders, Analyst Says
  9. iPhone 16 Remained Top Selling Smartphone For Second Consecutive Quarter Globally: Report
  10. Samsung Galaxy S25 FE Launched in India With 6.7-Inch AMOLED Screen, 50-Megapixel Camera: Price, Features
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.