![]() ![]() What is Spectre? Which processors are impacted?Ĭoming to Spectre, according to the Security Researchers, this “ exploit break down isolation between different applications.” The good news is that Spectre is harder to execute compared to ‘Meltdown’, but that also means the problem is harder to fix. Firmware updates for hardware will also be needed to fix this problem. Also the exploits are present on nearly all Intel processors produced in the last ten years or so, (from 1995 onward) which is a huge number considering the company powers a majority of the world’s PCs, etc. It is so named because it ‘melts’ boundaries, which should ideally remain around the protected memory. Meltdown is believed to impact only Intel processors. ![]() Meltdown enables a program to read the protected kernel memory, which should ideally be a strict no-no. What is Meltdown vulnerability? Which processors are impacted? CVE-2017-5754 is the official number for Meltdown (Image source: Bloomberg) Meltdown enable a process to read the protected kernel memory. According to Apple, unless a malicious app is running on the iOS or MacOS device, the vulnerability cannot be exploited. However, Google’s Project Zero report has also pointed out in order to successfully exploit the vulnerability, the attacker will still need access to the machine and should be able to run a malicious app or code on the concerned machine. These vulnerabilities also allow an attacker to use the Javascript running in the web browser to access protected memory, according to researchers. This can be exploited by malicious programs to access the kernel memory, which includes crucial data like passwords, encrypted information, etc. The problem is that this “Speculative execution” also relies on access to privileged ‘kernel memory’, which is supposed to remain protected. If the prediction is wrong, then the execution is rolled back. This exists to optimise performance and as the term indicates, the computer is guessing which command or path will be taken next. What is causing the security flaw on all modern processors?Īccording to researchers, the issue is due to a performance feature called ‘Speculative execution’ present on nearly all modern processors. Here’s everything you need to know about Meltdown and Spectre, and what can you do to keep your PC or device protected for now. Windows, Linux, iOS, MacOS, tvOS, Android and nearly all operating systems are impacted by these vulnerabilities. These impact nearly all modern processors used on computers, smartphones, tablets. Meltdown and Spectre are two processor level flaws that security researchers have highlighted. (Image source: Screenshot from Meltdown explainer website) Meltdown and Spectre are two processor level flaws impacting all devices with Intel, ARM processors etc. ![]()
0 Comments
Leave a Reply. |
AuthorWrite something about yourself. No need to be fancy, just an overview. ArchivesCategories |