• Home
  • Latest
  • Fortune 500
  • Finance
  • Tech
  • Leadership
  • Lifestyle
  • Rankings
  • Multimedia

Trendingnow

1

Trump, who has repeatedly called climate change fake, is now threatening Brazil with tariffs over the deforestation of the Amazon

2

Pentagon accuses Alibaba, Baidu and BYD, three of China's biggest companies, of supporting the Chinese military

3

'We are rapidly running out of time': Watchdog sounds Social Security alarm after 22% cut confirmed for 2032

1

Trump, who has repeatedly called climate change fake, is now threatening Brazil with tariffs over the deforestation of the Amazon

2

Pentagon accuses Alibaba, Baidu and BYD, three of China's biggest companies, of supporting the Chinese military

3

'We are rapidly running out of time': Watchdog sounds Social Security alarm after 22% cut confirmed for 2032
TechGoogle

Why Your Web Browser May Be Most Vulnerable to Spectre and What to Do About It

By
Aaron Pressman
Aaron Pressman
Down Arrow Button Icon
By
Aaron Pressman
Aaron Pressman
Down Arrow Button Icon
January 5, 2018, 1:36 PM ET

Security researchers this week revealed details of Spectre and Meltdown, massive security vulnerabilities found in microprocessors made by Intel, Advanced Micro Devices and others.

The attacks take advantage of a features built into modern chips and could allow hackers to craft malware using Spectre that could steal passwords or other confidential data through popular web browsers like Chrome, Internet Explorer, Firefox, and Safari for Macs or iOS. That’s prompted quick action from Microsoft, Google, Apple, and Firefox.

What is Spectre?

Spectre is the name given to two of the three kinds of newly discovered attacks that hackers could use to steal confidential data from computers and mobile devices. While the third attack, known as Meltdown, only runs on Intel chips, Spectre attacks can affect devices with virtually any modern processor.

The processors often handle data, like a password or encryption key, that is supposed to be kept from other apps. But to speed up calculations, chips use a technique known as speculative execution to try to guess at some answers that may be needed if a chain of calculations came out a certain way. Because of a predictable delay in the timing of the technique and a chip’s security checks, the researchers found that a rogue app could guess where confidential data was located in a chip’s memory and steal it.

Get Data Sheet, Fortune’s technology newsletter.

Why are web browsers vulnerable to Spectre?

An attacker would need to get a nefarious app running on a victim’s computer or phone to steal data using Spectre. The researchers who uncovered the security problems said they developed a successful model attack using one of the two Spectre variations via a Javascript program. So one way hackers could actually get their attack app to run on a victim’s computer is by writing a data stealing Javascript program and posting it on a web site. The victim’s browser app would automatically run the rogue code, assuming it just was an ordinary part of the site’s features.

Have any hackers used the attack yet?

The researchers who uncovered Spectre say they developed methods to use the vulnerabilities to steal user data (sometimes after being given confidential details of chip design by the chip makers). But no one has yet discovered any actual exploits “in the wild” yet.

How can I protect my web browser from Spectre?

Each browser maker is releasing updates that add new security features and, in some cases, turn off existing features that would make a Spectre attack easier.

Google says Chrome users should turn on a feature called “site isolation” that limits the ability of a rogue Javascript program to get access to sensitive data. The company also said it will release an update on or about Jan. 23 to Chrome’s Javascript feature that will protect better against Spectre attacks, though browser performance may suffer.

Microsoft (MSFT) says it has already issued a Windows security update for its Internet Explorer and Edge browser apps dubbed “KB4056890” to help protect against Spectre. The update changed browser features to make accessing confidential information in a device’s CPU via the timing delays much more difficult, the company said.

Mozilla, the company behind Firefox, said the newest releases of its apps changed several features to make Spectre attacks more difficult. Firefox version 57.0.4, released on Jan. 4, includes the mitigation techniques. But the company said it is studying additional ways to protect even more strongly against the attacks. “In the longer term, we have started experimenting with techniques to remove the information leak closer to the source, instead of just hiding the leak by disabling timers,” Mozilla said in a blog post. “This project requires time to understand, implement and test.”

Apple said it planned to release an update to Safari in “coming days” to protect against Spectre. Apple said early tests of the changes needed showed a minimal impact on browser performance.

What about protection from Meltdown attacks?

The third kind of attack, known as Meltdown, relies not on the delayed timing of speculative execution but on how chip software may not check if an app has permission to access some data used in speculative execution as a way to speed up performance. So far, Meltdown has only been demonstrated against chips made by Intel, not AMD (AMD). Apple says the attack “has the most potential to be exploited.”

To protect against Meltdown, chipmakers and operating system vendors are already issuing patches and updates. Intel (INTC), Google (GOOGL), and Apple (AAPL), among others, say they have already released recent patches to help protect against the attack.

About the Author
By Aaron Pressman
See full bioRight Arrow Button Icon

Latest in Tech

Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025

Most Popular

Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Fortune Secondary Logo
Rankings
  • 100 Best Companies
  • Fortune 500
  • Global 500
  • Fortune 500 Europe
  • Most Powerful Women
  • World's Most Admired Companies
  • See All Rankings
  • Lists Calendar
Sections
  • Finance
  • Fortune Crypto
  • Features
  • Leadership
  • Health
  • Commentary
  • Success
  • Retail
  • Mpw
  • Tech
  • Lifestyle
  • CEO Initiative
  • Asia
  • Politics
  • Conferences
  • Europe
  • Newsletters
  • Personal Finance
  • Environment
  • Magazine
  • Education
Customer Support
  • Frequently Asked Questions
  • Customer Service Portal
  • Privacy Policy
  • Terms Of Use
  • Single Issues For Purchase
  • International Print
Commercial Services
  • Advertising
  • Fortune Brand Studio
  • Fortune Analytics
  • Fortune Conferences
  • Business Development
  • Group Subscriptions
About Us
  • About Us
  • Press Center
  • Work At Fortune
  • Terms And Conditions
  • Site Map
  • About Us
  • Press Center
  • Work At Fortune
  • Terms And Conditions
  • Site Map
  • Facebook icon
  • Twitter icon
  • LinkedIn icon
  • Instagram icon
  • Pinterest icon

Latest in Tech

A trader works on the floor of the New York Stock Exchange (NYSE) in New York, US, on Wednesday, June 3, 2026
InvestingWall Street
Wall Street dumped nearly $1 trillion in tech stocks by midday—then clawed it back and bought peanut butter and paint
By Eva RoytburgJune 9, 2026
4 hours ago
AI isn’t replacing Hyatt’s salespeople—it’s freeing up a full day of work every week, according to the CEO
AIBrainstorm Tech
AI isn’t replacing Hyatt’s salespeople—it’s freeing up a full day of work every week, according to the CEO
By Sharon GoldmanJune 9, 2026
4 hours ago
America’s grid is reeling. General Motors offers itself as a distributed utility in disguise
EnergyAutos
America’s grid is reeling. General Motors offers itself as a distributed utility in disguise
By Nick LichtenbergJune 9, 2026
4 hours ago
Tesla cofounder: ‘We should be really worried’ about the U.S. grid as China speeds ahead in the power race
EnergyBrainstorm Tech
Tesla cofounder: ‘We should be really worried’ about the U.S. grid as China speeds ahead in the power race
By Jordan BlumJune 9, 2026
5 hours ago
The AI industry spent years chasing bigger models. Now it’s chasing efficiency
AIBrainstorm Tech
The AI industry spent years chasing bigger models. Now it’s chasing efficiency
By Sharon GoldmanJune 9, 2026
6 hours ago
Xbox CEO Asha Sharma speaks on stage at Fortune Brainstorm Tech 2026.
Big TechMicrosoft
‘Not an Allbirds Moment’: Xbox’s new CEO says she is grounding the console in gaming roots, not AI
By Sebastian HerreraJune 9, 2026
6 hours ago

Most Popular

Trump, who has repeatedly called climate change fake, is now threatening Brazil with tariffs over the deforestation of the Amazon
Environment
Trump, who has repeatedly called climate change fake, is now threatening Brazil with tariffs over the deforestation of the Amazon
By Sasha RogelbergJune 8, 2026
1 day ago
Pentagon accuses Alibaba, Baidu and BYD, three of China's biggest companies, of supporting the Chinese military
Asia
Pentagon accuses Alibaba, Baidu and BYD, three of China's biggest companies, of supporting the Chinese military
By Kate O'Keeffe and BloombergJune 8, 2026
1 day ago
'We are rapidly running out of time': Watchdog sounds Social Security alarm after 22% cut confirmed for 2032
Economy
'We are rapidly running out of time': Watchdog sounds Social Security alarm after 22% cut confirmed for 2032
By Nick LichtenbergJune 9, 2026
9 hours ago
Current price of oil as of June 8, 2026
Personal Finance
Current price of oil as of June 8, 2026
By Joseph HostetlerJune 8, 2026
2 days ago
Gen Zers are arriving at college unable to even read a sentence—professors warn it could lead to a generation of anxious and lonely graduates
Success
Gen Zers are arriving at college unable to even read a sentence—professors warn it could lead to a generation of anxious and lonely graduates
By Preston ForeJune 7, 2026
2 days ago
Costco CEO Ron Vachris rose from forklift driver to the C-suite without a college degree: ‘Don’t chase a title’ is the career advice that got him there
Success
Costco CEO Ron Vachris rose from forklift driver to the C-suite without a college degree: ‘Don’t chase a title’ is the career advice that got him there
By Preston ForeJune 8, 2026
1 day ago

© 2026 Fortune Media IP Limited. All Rights Reserved. Use of this site constitutes acceptance of our Terms of Use and Privacy Policy | CA Notice at Collection and Privacy Notice | Do Not Sell/Share My Personal Information
FORTUNE is a trademark of Fortune Media IP Limited, registered in the U.S. and other countries. FORTUNE may receive compensation for some links to products and services on this website. Offers may be subject to change without notice.