cassec.blogg.se

How to update google chrome due to spectre and meltdown
How to update google chrome due to spectre and meltdown













how to update google chrome due to spectre and meltdown

Intel declared that performance degradations are “workload-dependent,” and “for the average computer user, should not be significant and will be mitigated over time.” The problem is that these fixes seem to have a performance impact, some appreciating it up to 30%. As that is not practically possible, a software solution has been deployed or it is in the works. The real solution, as CERT mentions, is to replace the system’s CPU with one that does not show the vulnerability. Android is also affected, as are Apple’s iOS and tvOS (though not watchOS). Most operating systems in use are affected, including Linux, MacOS, and Windows. These vulnerabilities are considered to be critical. For detailed information on these vulnerabilities and what it takes to exploit them, we recommend reading this Google Project Zero post, the Meltdown ( PDF) and Spectre ( PDF) research papers.

how to update google chrome due to spectre and meltdown how to update google chrome due to spectre and meltdown

Spectre affects all major CPUs – AMD, ARM, and Intel. AMD processors do not seem to be affected by Meltdown. Certain ARM processors are vulnerable to a variant of this flaw which leaves the content of certain CPU registries available to other processes. Researchers have executed test exploits on several Intel processors going back to models from 2011. Meltdown affects out-of-order execution Intel processors possibly going back to models from 1995. Spectre enables one process to access the memory space of another process, making data vulnerable to be read. Meltdown enables one process to access some of the kernel memory of the operating system leaving sensitive data exposed. The issue was reported by Google to the respective processor makers in June last year. This is a low-level hardware issue affecting many models of Intel, AMD and ARM CPUs. Called Meltdown and Spectre, the vulnerabilities use the CPU “ speculative execution” to make virtual memory available to unintended processes, possibly leading to data being read by processes not owning it. Google Project Zero and a number of researchers have discovered and made available details on two hardware flaws that affect the security of most desktop and mobile devices. This article discusses the latest CPU vulnerabilities – Meltdown and Spectre – and the current solutions to fix them.















How to update google chrome due to spectre and meltdown