Researchers including Google’s Project Zero disclosed Meltdown and Spectre, flaws in the way modern processors perform speculative execution. They affected chips from Intel, AMD, and Arm, used in most computers, phones, and cloud servers. Researchers from several universities and companies found the flaws independently.
What happened
- The flaws could allow malicious programs to read data from memory that should be protected, such as passwords and encryption keys.
- Meltdown mainly affected Intel processors, while Spectre affected a wider range of chips and was harder to fix.
- Details were published earlier than planned on 3 January 2018 after media reports began to reveal the issue.
- Operating system, browser, and firmware updates were released, some of which caused performance or stability problems.
Why it mattered
Meltdown and Spectre showed that hardware itself could be a source of serious vulnerabilities, affecting cloud providers and consumers alike, and they started years of research into similar flaws.
Lessons for organisations
Keep operating systems, firmware, and browsers updated, and understand how cloud providers are managing shared infrastructure risks. Test patches before wide deployment where performance matters.
Source: Google Project Zero
Part of our Top stories archive of headline-making events in information security, privacy, and AI. If you would like help applying the lessons to your organisation, contact us.