• Home
  • Latest
  • Fortune 500
  • Finance
  • Tech
  • Leadership
  • Lifestyle
  • Rankings
  • Multimedia
TechGoogle

Why Your Web Browser May Be Most Vulnerable to Spectre and What to Do About It

By
Aaron Pressman
Aaron Pressman
Down Arrow Button Icon
By
Aaron Pressman
Aaron Pressman
Down Arrow Button Icon
January 5, 2018, 1:36 PM ET

Security researchers this week revealed details of Spectre and Meltdown, massive security vulnerabilities found in microprocessors made by Intel, Advanced Micro Devices and others.

The attacks take advantage of a features built into modern chips and could allow hackers to craft malware using Spectre that could steal passwords or other confidential data through popular web browsers like Chrome, Internet Explorer, Firefox, and Safari for Macs or iOS. That’s prompted quick action from Microsoft, Google, Apple, and Firefox.

What is Spectre?

Spectre is the name given to two of the three kinds of newly discovered attacks that hackers could use to steal confidential data from computers and mobile devices. While the third attack, known as Meltdown, only runs on Intel chips, Spectre attacks can affect devices with virtually any modern processor.

The processors often handle data, like a password or encryption key, that is supposed to be kept from other apps. But to speed up calculations, chips use a technique known as speculative execution to try to guess at some answers that may be needed if a chain of calculations came out a certain way. Because of a predictable delay in the timing of the technique and a chip’s security checks, the researchers found that a rogue app could guess where confidential data was located in a chip’s memory and steal it.

Get Data Sheet, Fortune’s technology newsletter.

Why are web browsers vulnerable to Spectre?

An attacker would need to get a nefarious app running on a victim’s computer or phone to steal data using Spectre. The researchers who uncovered the security problems said they developed a successful model attack using one of the two Spectre variations via a Javascript program. So one way hackers could actually get their attack app to run on a victim’s computer is by writing a data stealing Javascript program and posting it on a web site. The victim’s browser app would automatically run the rogue code, assuming it just was an ordinary part of the site’s features.

Have any hackers used the attack yet?

The researchers who uncovered Spectre say they developed methods to use the vulnerabilities to steal user data (sometimes after being given confidential details of chip design by the chip makers). But no one has yet discovered any actual exploits “in the wild” yet.

How can I protect my web browser from Spectre?

Each browser maker is releasing updates that add new security features and, in some cases, turn off existing features that would make a Spectre attack easier.

Google says Chrome users should turn on a feature called “site isolation” that limits the ability of a rogue Javascript program to get access to sensitive data. The company also said it will release an update on or about Jan. 23 to Chrome’s Javascript feature that will protect better against Spectre attacks, though browser performance may suffer.

Microsoft (MSFT) says it has already issued a Windows security update for its Internet Explorer and Edge browser apps dubbed “KB4056890” to help protect against Spectre. The update changed browser features to make accessing confidential information in a device’s CPU via the timing delays much more difficult, the company said.

Mozilla, the company behind Firefox, said the newest releases of its apps changed several features to make Spectre attacks more difficult. Firefox version 57.0.4, released on Jan. 4, includes the mitigation techniques. But the company said it is studying additional ways to protect even more strongly against the attacks. “In the longer term, we have started experimenting with techniques to remove the information leak closer to the source, instead of just hiding the leak by disabling timers,” Mozilla said in a blog post. “This project requires time to understand, implement and test.”

Apple said it planned to release an update to Safari in “coming days” to protect against Spectre. Apple said early tests of the changes needed showed a minimal impact on browser performance.

What about protection from Meltdown attacks?

The third kind of attack, known as Meltdown, relies not on the delayed timing of speculative execution but on how chip software may not check if an app has permission to access some data used in speculative execution as a way to speed up performance. So far, Meltdown has only been demonstrated against chips made by Intel, not AMD (AMD). Apple says the attack “has the most potential to be exploited.”

To protect against Meltdown, chipmakers and operating system vendors are already issuing patches and updates. Intel (INTC), Google (GOOGL), and Apple (AAPL), among others, say they have already released recent patches to help protect against the attack.

About the Author
By Aaron Pressman
See full bioRight Arrow Button Icon

Latest in Tech

Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025

Most Popular

Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Fortune Secondary Logo
Rankings
  • 100 Best Companies
  • Fortune 500
  • Global 500
  • Fortune 500 Europe
  • Most Powerful Women
  • Future 50
  • World’s Most Admired Companies
  • See All Rankings
Sections
  • Finance
  • Fortune Crypto
  • Features
  • Leadership
  • Health
  • Commentary
  • Success
  • Retail
  • Mpw
  • Tech
  • Lifestyle
  • CEO Initiative
  • Asia
  • Politics
  • Conferences
  • Europe
  • Newsletters
  • Personal Finance
  • Environment
  • Magazine
  • Education
Customer Support
  • Frequently Asked Questions
  • Customer Service Portal
  • Privacy Policy
  • Terms Of Use
  • Single Issues For Purchase
  • International Print
Commercial Services
  • Advertising
  • Fortune Brand Studio
  • Fortune Analytics
  • Fortune Conferences
  • Business Development
  • Group Subscriptions
About Us
  • About Us
  • Editorial Calendar
  • Press Center
  • Work At Fortune
  • Diversity And Inclusion
  • Terms And Conditions
  • Site Map
  • About Us
  • Editorial Calendar
  • Press Center
  • Work At Fortune
  • Diversity And Inclusion
  • Terms And Conditions
  • Site Map
  • Facebook icon
  • Twitter icon
  • LinkedIn icon
  • Instagram icon
  • Pinterest icon

Latest in Tech

Ukraine will have the most important defense industrial base in the free world, former CIA chief predicts
InnovationDefense
Ukraine will have the most important defense industrial base in the free world, former CIA chief predicts
By Jason MaApril 10, 2026
27 minutes ago
A hacker in a dark hoodie and wearing a creepy white mask sits at a keyboard in front of multiple computer monitors in a dark, blue-shaded room.
CybersecurityAnthropic
Anthropic is limiting access to its latest AI model, Mythos. The real risks may already be out there
By Beatrice NolanApril 10, 2026
28 minutes ago
‘Downward mobility is incredibly radicalizing’: The college bargain is broken. What comes next could reshape America
EconomyColleges and Universities
‘Downward mobility is incredibly radicalizing’: The college bargain is broken. What comes next could reshape America
By Nick LichtenbergApril 10, 2026
3 hours ago
Who’s really in control as AI and Big Tech race ahead?
MagazineEurope
Who’s really in control as AI and Big Tech race ahead?
By Francesca CassidyApril 10, 2026
5 hours ago
Photo: Donald Trump
EconomyMarkets
U.S. and Iran begin peace talks as Trump’s White House goes to war against the media, insider traders, and the Pope
By Jim EdwardsApril 10, 2026
6 hours ago
Fortune Brainstorm Tech 2019 in Aspen, Colo. (Photo: Fortune)
NewslettersFortune Tech
Who’s speaking at Fortune Brainstorm Tech 2026
By Andrew NuscaApril 10, 2026
7 hours ago

Most Popular

The U.S. government is spending $88 billion a month in interest on national debt—equal to spending on defense and education combined
Economy
The U.S. government is spending $88 billion a month in interest on national debt—equal to spending on defense and education combined
By Fortune EditorsApril 9, 2026
1 day ago
A Meta employee created a dashboard so coworkers can compete to be the company's No. 1 AI token user—and Zuckerberg doesn't even rank in the top 250
AI
A Meta employee created a dashboard so coworkers can compete to be the company's No. 1 AI token user—and Zuckerberg doesn't even rank in the top 250
By Fortune EditorsApril 9, 2026
1 day ago
Mark Cuban admits he made a mistake letting go of the Mavericks: 'I don't regret selling. I regret who I sold to'
Investing
Mark Cuban admits he made a mistake letting go of the Mavericks: 'I don't regret selling. I regret who I sold to'
By Fortune EditorsApril 9, 2026
24 hours ago
Gen Z doesn't want your full-time job. They want several part-time roles, and it's reshaping the entire workforce
Success
Gen Z doesn't want your full-time job. They want several part-time roles, and it's reshaping the entire workforce
By Fortune EditorsApril 9, 2026
1 day ago
'I hate working 5 days': Zoom CEO says traditional work schedules are becoming obsolete—and predicts a 3-day workweek by 2031
Success
'I hate working 5 days': Zoom CEO says traditional work schedules are becoming obsolete—and predicts a 3-day workweek by 2031
By Fortune EditorsApril 9, 2026
1 day ago
Current price of oil as of April 9, 2026
Personal Finance
Current price of oil as of April 9, 2026
By Fortune EditorsApril 9, 2026
1 day ago

© 2026 Fortune Media IP Limited. All Rights Reserved. Use of this site constitutes acceptance of our Terms of Use and Privacy Policy | CA Notice at Collection and Privacy Notice | Do Not Sell/Share My Personal Information
FORTUNE is a trademark of Fortune Media IP Limited, registered in the U.S. and other countries. FORTUNE may receive compensation for some links to products and services on this website. Offers may be subject to change without notice.