• Home
  • Latest
  • Fortune 500
  • Finance
  • Tech
  • Leadership
  • Lifestyle
  • Rankings
  • Multimedia

Trendingnow

1

Microsoft AI chief gives it 18 months—for all white-collar work to be automated by AI

2

Former top Russian official admits the country is over Putin and can 'imagine a future without him' — even elites bail as Kremlin seizes their assets 

3

Meet the 20-year-old CEO who launched a company in high school to solve Gen Z's entry-level job crisis

1

Microsoft AI chief gives it 18 months—for all white-collar work to be automated by AI

2

Former top Russian official admits the country is over Putin and can 'imagine a future without him' — even elites bail as Kremlin seizes their assets 

3

Meet the 20-year-old CEO who launched a company in high school to solve Gen Z's entry-level job crisis
TechGoogle

Why Your Web Browser May Be Most Vulnerable to Spectre and What to Do About It

By
Aaron Pressman
Aaron Pressman
Down Arrow Button Icon
By
Aaron Pressman
Aaron Pressman
Down Arrow Button Icon
January 5, 2018, 1:36 PM ET

Security researchers this week revealed details of Spectre and Meltdown, massive security vulnerabilities found in microprocessors made by Intel, Advanced Micro Devices and others.

The attacks take advantage of a features built into modern chips and could allow hackers to craft malware using Spectre that could steal passwords or other confidential data through popular web browsers like Chrome, Internet Explorer, Firefox, and Safari for Macs or iOS. That’s prompted quick action from Microsoft, Google, Apple, and Firefox.

What is Spectre?

Spectre is the name given to two of the three kinds of newly discovered attacks that hackers could use to steal confidential data from computers and mobile devices. While the third attack, known as Meltdown, only runs on Intel chips, Spectre attacks can affect devices with virtually any modern processor.

The processors often handle data, like a password or encryption key, that is supposed to be kept from other apps. But to speed up calculations, chips use a technique known as speculative execution to try to guess at some answers that may be needed if a chain of calculations came out a certain way. Because of a predictable delay in the timing of the technique and a chip’s security checks, the researchers found that a rogue app could guess where confidential data was located in a chip’s memory and steal it.

Get Data Sheet, Fortune’s technology newsletter.

Why are web browsers vulnerable to Spectre?

An attacker would need to get a nefarious app running on a victim’s computer or phone to steal data using Spectre. The researchers who uncovered the security problems said they developed a successful model attack using one of the two Spectre variations via a Javascript program. So one way hackers could actually get their attack app to run on a victim’s computer is by writing a data stealing Javascript program and posting it on a web site. The victim’s browser app would automatically run the rogue code, assuming it just was an ordinary part of the site’s features.

Have any hackers used the attack yet?

The researchers who uncovered Spectre say they developed methods to use the vulnerabilities to steal user data (sometimes after being given confidential details of chip design by the chip makers). But no one has yet discovered any actual exploits “in the wild” yet.

How can I protect my web browser from Spectre?

Each browser maker is releasing updates that add new security features and, in some cases, turn off existing features that would make a Spectre attack easier.

Google says Chrome users should turn on a feature called “site isolation” that limits the ability of a rogue Javascript program to get access to sensitive data. The company also said it will release an update on or about Jan. 23 to Chrome’s Javascript feature that will protect better against Spectre attacks, though browser performance may suffer.

Microsoft (MSFT) says it has already issued a Windows security update for its Internet Explorer and Edge browser apps dubbed “KB4056890” to help protect against Spectre. The update changed browser features to make accessing confidential information in a device’s CPU via the timing delays much more difficult, the company said.

Mozilla, the company behind Firefox, said the newest releases of its apps changed several features to make Spectre attacks more difficult. Firefox version 57.0.4, released on Jan. 4, includes the mitigation techniques. But the company said it is studying additional ways to protect even more strongly against the attacks. “In the longer term, we have started experimenting with techniques to remove the information leak closer to the source, instead of just hiding the leak by disabling timers,” Mozilla said in a blog post. “This project requires time to understand, implement and test.”

Apple said it planned to release an update to Safari in “coming days” to protect against Spectre. Apple said early tests of the changes needed showed a minimal impact on browser performance.

What about protection from Meltdown attacks?

The third kind of attack, known as Meltdown, relies not on the delayed timing of speculative execution but on how chip software may not check if an app has permission to access some data used in speculative execution as a way to speed up performance. So far, Meltdown has only been demonstrated against chips made by Intel, not AMD (AMD). Apple says the attack “has the most potential to be exploited.”

To protect against Meltdown, chipmakers and operating system vendors are already issuing patches and updates. Intel (INTC), Google (GOOGL), and Apple (AAPL), among others, say they have already released recent patches to help protect against the attack.

About the Author
By Aaron Pressman
See full bioRight Arrow Button Icon

Latest in Tech

Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025

Most Popular

Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Fortune Secondary Logo
Rankings
  • 100 Best Companies
  • Fortune 500
  • Global 500
  • Fortune 500 Europe
  • Most Powerful Women
  • World's Most Admired Companies
  • See All Rankings
  • Lists Calendar
Sections
  • Finance
  • Fortune Crypto
  • Features
  • Leadership
  • Health
  • Commentary
  • Success
  • Retail
  • Mpw
  • Tech
  • Lifestyle
  • CEO Initiative
  • Asia
  • Politics
  • Conferences
  • Europe
  • Newsletters
  • Personal Finance
  • Environment
  • Magazine
  • Education
Customer Support
  • Frequently Asked Questions
  • Customer Service Portal
  • Privacy Policy
  • Terms Of Use
  • Single Issues For Purchase
  • International Print
Commercial Services
  • Advertising
  • Fortune Brand Studio
  • Fortune Analytics
  • Fortune Conferences
  • Business Development
  • Group Subscriptions
About Us
  • About Us
  • Press Center
  • Work At Fortune
  • Terms And Conditions
  • Site Map
  • About Us
  • Press Center
  • Work At Fortune
  • Terms And Conditions
  • Site Map
  • Facebook icon
  • Twitter icon
  • LinkedIn icon
  • Instagram icon
  • Pinterest icon

Latest in Tech

New NRG Energy CEO leans into growth with ‘bring your own power’ for the AI boom and affordability with ‘virtual power plants’
Energypower
New NRG Energy CEO leans into growth with ‘bring your own power’ for the AI boom and affordability with ‘virtual power plants’
By Jordan BlumMay 17, 2026
19 minutes ago
AI poised to tilt job market leverage toward older workers
AIHiring
AI poised to tilt job market leverage toward older workers
By Victor Swezey and BloombergMay 16, 2026
8 hours ago
SpaceX heads into a record-shattering IPO with the ‘deepest moat that exists today’ as investors vow to ‘never bet against Elon’
InnovationIPOs
SpaceX heads into a record-shattering IPO with the ‘deepest moat that exists today’ as investors vow to ‘never bet against Elon’
By Jason MaMay 16, 2026
15 hours ago
tarot
AICulture
We talked to 12 tarot card readers who are using AI. They split in 2 camps, with big implications for the technology
By Ziv Epstein, Farnaz Jahanbakhsh, Vana Goblot and The ConversationMay 16, 2026
16 hours ago
liberman
Commentarystart-ups
We watched social media concentrate. The same thing is happening in AI, only at a deeper layer
By David Liberman and Daniil LibermanMay 16, 2026
18 hours ago
mustafa suleyman
AIMicrosoft
Microsoft AI chief gives it 18 months—for all white-collar work to be automated by AI
By Jake AngeloMay 16, 2026
19 hours ago

Most Popular

Microsoft AI chief gives it 18 months—for all white-collar work to be automated by AI
AI
Microsoft AI chief gives it 18 months—for all white-collar work to be automated by AI
By Jake AngeloMay 16, 2026
19 hours ago
Former top Russian official admits the country is over Putin and can 'imagine a future without him' — even elites bail as Kremlin seizes their assets 
Politics
Former top Russian official admits the country is over Putin and can 'imagine a future without him' — even elites bail as Kremlin seizes their assets 
By Jason MaMay 16, 2026
9 hours ago
Meet the 20-year-old CEO who launched a company in high school to solve Gen Z's entry-level job crisis
Future of Work
Meet the 20-year-old CEO who launched a company in high school to solve Gen Z's entry-level job crisis
By Jake AngeloMay 16, 2026
23 hours ago
The Bezos family just donated $100 million to help achieve one of Mayor Zohran Mamdani’s top campaign promises
Politics
The Bezos family just donated $100 million to help achieve one of Mayor Zohran Mamdani’s top campaign promises
By Jake AngeloMay 12, 2026
4 days ago
‘You’re not a hero, you’re a liability’: Shark Tank’s Kevin O’Leary warns Gen Z founders to stop glorifying hustle culture
Future of Work
‘You’re not a hero, you’re a liability’: Shark Tank’s Kevin O’Leary warns Gen Z founders to stop glorifying hustle culture
By Jacqueline MunisMay 16, 2026
19 hours ago
Despite having a $165 million net worth, Scarlett Johansson says work-life balance doesn’t exist—and the first step to success is admitting that
Success
Despite having a $165 million net worth, Scarlett Johansson says work-life balance doesn’t exist—and the first step to success is admitting that
By Preston ForeMay 13, 2026
4 days ago

© 2026 Fortune Media IP Limited. All Rights Reserved. Use of this site constitutes acceptance of our Terms of Use and Privacy Policy | CA Notice at Collection and Privacy Notice | Do Not Sell/Share My Personal Information
FORTUNE is a trademark of Fortune Media IP Limited, registered in the U.S. and other countries. FORTUNE may receive compensation for some links to products and services on this website. Offers may be subject to change without notice.