• Home
  • Latest
  • Fortune 500
  • Finance
  • Tech
  • Leadership
  • Lifestyle
  • Rankings
  • Multimedia
TechIntel

Understanding Those Alarming Computer Chip Security Holes: ‘Meltdown’ and ‘Spectre’

Robert Hackett
By
Robert Hackett
Robert Hackett
Down Arrow Button Icon
Robert Hackett
By
Robert Hackett
Robert Hackett
Down Arrow Button Icon
January 4, 2018, 9:54 AM ET

A bomb cyclone hit the IT world on Wednesday as tech giants and computer security researchers released details pertaining to two major security holes that affect the processors in almost all computers. Researchers, including ones employed by the likes of Google, various tech firms, and academic institutions, independently discovered the flaws last year.

The vulnerabilities could allow attackers to swipe sensitive secrets from the memory of almost all devices, including phones, tablets, PCs, and computer servers. Experts have warned that hackers could develop exploits to purloin personal data, passwords, cryptographic keys, and other supposedly inaccessible information from targets.

Several programmers have already demonstrated proofs of concept for these so-called side channel attacks.

Using #Meltdown to steal passwords in real time #intelbug #kaiser #kpti /cc @mlqxyz @lavados @StefanMangard @yuvalyarom https://t.co/gX4CxfL1Ax pic.twitter.com/JbEvQSQraP

— Michael Schwarz (@misc0110) January 4, 2018

Silicon Scars

The flaws plague hardware produced by top chip makers like Intel (INTC) and Advanced Micro Devices (AMD), and Softbank-owned chip designer ARM Holdings. Big tech companies including Microsoft (MSFT) and Apple (AAPL) have been scrambling in recent weeks to address these threats by developing fixes for their software while cloud computing giants, like Amazon (AMZN) and Google (GOOG), have been rushing to apply patches to their data center infrastructure.

The first attack, dubbed “Meltdown,” applies specifically to Intel chips and allows hackers to circumvent the isolation barrier between user applications and operating systems, thereby opening up access to otherwise restricted machine memory. The second attack, “Spectre,” which is harder to pull off but has no available patches, lets hackers pry secrets out of the memory of devices running Intel, AMD, and ARM chips.

The Meltdown Mess

Per Meltdown, Apple and Microsoft have produced patches for Windows and macOS, as has the open source Linux project for its namesake operating system, although implementing these mitigations could cause computers to slow down by as much as 30%, researchers say. At the scale of a data center, such a performance hit could be severely detrimental to operations.

Intel countered in a statement that “any performance impacts are workload-dependent, and, for the average computer user, should not be significant and will be mitigated over time.”

Get Data Sheet, Fortune’s technology newsletter.

Amazon, Google, and Microsoft have all been applying the patches to their data center systems this week, the companies said. The companies were, in some cases, forced to act sooner than anticipated as news of the chip flaws began to trickle out online, causing the corporations to advance their disclosure timelines by a week.

Big Tech’s Response

Google, whose security researcher Jann Horn of the Project Zero team (see this Fortune profile of that ace hacker squad from last year) discovered both flaws, first alerted Intel to the problem, giving the company a headstart on the process. Other independent discoverers of Meltdown included Werner Haas and Thomas Prescher of Cyberus Technology and Daniel Gruss, Moritz Lipp, Stefan Mangard, and Michael Schwarz of Austria’s Graz University of Technology.

“We have updated our systems and affected products to protect against this new type of attack,” Google said in a statement Wednesday.

Microsoft said in a statement Wednesday that it had updated “the majority” of its Azure cloud infrastructure, though some aspects “are still being updated and require a reboot of customer [virtual machines] for the security update to take effect.” Official updates were originally expected to arrive as part of one of the company’s upcoming Patch Tuesdays on January 9th (though the company has been testing beta versions of the patches since November).

“The majority of Azure customers should not see a noticeable performance impact with this update,” Microsoft said.

Amazon issued a similar statement Wednesday: “All but a small single-digit percentage of instances across the Amazon EC2 fleet are already protected. The remaining ones will be completed in the next several hours, with associated instance maintenance notifications.”

Haunted by Spectre

Spectre—the more pervasive and more difficult to take advantage of the two flaws—has no clear solution as yet. While the U.S. Department of Homeland Security’s computer security advisory group US-CERT has suggested replacing affected CPUs, industry experts have countered that the recommendation is unfeasible.

Consumers and businesses should look to apply patches and workarounds if and when those become available.

Spectre’s discoverers include Google Project Zero’s Jann Horn, independent security researcher Paul Kocher, Daniel Genkin at the University of Pennsylvania and University of Maryland, Mike Hamburg at the American tech firm Rambus, Moritz Lipp at Austria’s Graz University of Technology, and Yuval Yarom of Australia’s University of Adelaide.

“It is not easy to fix, it will haunt us for quite some time,” Spectre’s discoverers warned.

About the Author
Robert Hackett
By Robert Hackett
Instagram iconLinkedIn iconTwitter icon
See full bioRight Arrow Button Icon

Latest in Tech

Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025

Most Popular

Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Fortune Secondary Logo
Rankings
  • 100 Best Companies
  • Fortune 500
  • Global 500
  • Fortune 500 Europe
  • Most Powerful Women
  • World's Most Admired Companies
  • See All Rankings
  • Lists Calendar
Sections
  • Finance
  • Fortune Crypto
  • Features
  • Leadership
  • Health
  • Commentary
  • Success
  • Retail
  • Mpw
  • Tech
  • Lifestyle
  • CEO Initiative
  • Asia
  • Politics
  • Conferences
  • Europe
  • Newsletters
  • Personal Finance
  • Environment
  • Magazine
  • Education
Customer Support
  • Frequently Asked Questions
  • Customer Service Portal
  • Privacy Policy
  • Terms Of Use
  • Single Issues For Purchase
  • International Print
Commercial Services
  • Advertising
  • Fortune Brand Studio
  • Fortune Analytics
  • Fortune Conferences
  • Business Development
  • Group Subscriptions
About Us
  • About Us
  • Press Center
  • Work At Fortune
  • Terms And Conditions
  • Site Map
  • About Us
  • Press Center
  • Work At Fortune
  • Terms And Conditions
  • Site Map
  • Facebook icon
  • Twitter icon
  • LinkedIn icon
  • Instagram icon
  • Pinterest icon

Latest in Tech

hollywood
CommentaryMarketing
I spent 20 years learning to navigate an industry. Then I built a campaign for the man who’s dismantling it
By Matti YahavApril 29, 2026
1 hour ago
Current price of Ethereum for April 29, 2026
Personal FinanceEthereum
Current price of Ethereum for April 29, 2026
By Joseph HostetlerApril 29, 2026
1 hour ago
An excavator works to clear rubble after the East Wing of the White House was demolished on October 23, 2025 in Washington, DC. The demolition is part of U.S. President Donald Trump's plan to build a multimillion-dollar ballroom on the eastern side of the White House.
PoliticsWhite House
Meet all 37 White House ballroom donors funding the $400 million build, including Silicon Valley tech giants, crypto bros and the Lutnicks
By Nino Paoli and Fortune EditorsApril 29, 2026
2 hours ago
gen z
Commentarydisruption
AI won’t kill your job — it will kill the path to your first one
By Jeffrey Sonnenfeld, Stephen Henriques, Johan Griesel, Andrew Alam-Nist and Peter YuApril 29, 2026
3 hours ago
Christina Cacioppo poses while sitting down in a suit jacket
NewslettersTerm Sheet
Exclusive: Vanta hits $300 million ARR as ‘shadow AI’ explodes across corporate America
By Lily Mae LazarusApril 29, 2026
5 hours ago
Tariff-proof pay: How boardrooms quietly made sure Trump’s trade war stopped at the CEO’s door
Big TechMarkets
Tariff-proof pay: How boardrooms quietly made sure Trump’s trade war stopped at the CEO’s door
By Jim EdwardsApril 29, 2026
5 hours ago

Most Popular

Apple cofounder Ronald Wayne—whose stake would be worth up to $400 billion had he not sold it in 1976—says that at 91, he has no regrets
Success
Apple cofounder Ronald Wayne—whose stake would be worth up to $400 billion had he not sold it in 1976—says that at 91, he has no regrets
By Preston ForeApril 27, 2026
2 days ago
‘The cost of compute is far beyond the costs of the employees’: Nvidia executive says right now AI is more expensive than paying human workers
AI
‘The cost of compute is far beyond the costs of the employees’: Nvidia executive says right now AI is more expensive than paying human workers
By Sasha RogelbergApril 28, 2026
1 day ago
The U.S. military may have already used up half of its most expensive missiles, and it could take up to 4 years to rebuild its stockpiles
Politics
The U.S. military may have already used up half of its most expensive missiles, and it could take up to 4 years to rebuild its stockpiles
By Sasha RogelbergApril 24, 2026
5 days ago
Current price of gold as of April 28, 2026
Personal Finance
Current price of gold as of April 28, 2026
By Danny BakstApril 28, 2026
1 day ago
'Take the money and run': Johns Hopkins economist Steve Hanke on why the UAE quit OPEC
Energy
'Take the money and run': Johns Hopkins economist Steve Hanke on why the UAE quit OPEC
By Shawn TullyApril 29, 2026
8 hours ago
Current price of silver as of Tuesday, April 28, 2026
Personal Finance
Current price of silver as of Tuesday, April 28, 2026
By Joseph HostetlerApril 28, 2026
1 day ago

© 2026 Fortune Media IP Limited. All Rights Reserved. Use of this site constitutes acceptance of our Terms of Use and Privacy Policy | CA Notice at Collection and Privacy Notice | Do Not Sell/Share My Personal Information
FORTUNE is a trademark of Fortune Media IP Limited, registered in the U.S. and other countries. FORTUNE may receive compensation for some links to products and services on this website. Offers may be subject to change without notice.