Apple Confirms All Mac, iOS Devices Affected By Meltdown & Spectre Bugs

Apple Confirms All Mac, iOS Devices Affected By Meltdown & Spectre Bugs

Apple Confirms All Mac, iOS Devices Affected By Meltdown & Spectre Bugs

The company says that watchOS is not affected by Meltdown. They both rely on the ability to very precisely measure time to deliver exploits that leak memory data.

The scramble to harden a broad array of devices comes after researchers found two significant vulnerabilities within modern computing hardware, one of which can not be fully resolved as of yet.

The vulnerabilities, named Meltdown and Spectre, could allow hackers to steal sensitive information, including passwords, and affected millions of machines using Intel and AMD computer chips.

Analysis of these techniques revealed that while they are extremely hard to exploit, even by an app running locally on a Mac or iOS device, they can be potentially exploited in JavaScript running in a web browser. "This might include your passwords stored in a password manager or browser, your personal photos, emails, instant messages and even business-critical documents", according to a website created about the bugs. Web-based attacks are the most risky because they are easier to carry out.

"Every Intel processor which implements out-of-order execution is potentially affected, which is effectively every processor since 1995 (except Intel Itanium and Intel Atom before 2013)".

Those companies make the most popular processors, which means a huge range of popular computing devices are at risk.

Patch management is a critically important tool for staying on top of fixes for vulnerabilities like Meltdown and Spectre.

More news: Boca Juniors president: 'No Arsenal bids for Cristian Pavon'
More news: Snow for Alabama again? It's possible later this week
More news: Huawei officially introduces the Mate 10 Pro to the USA market

Essentially, the vulnerabilities affect the kernel of the chips and could allow an attacker to read information that should otherwise be inaccessible.

"Spectre breaks the isolation between different applications".

Intel, AMD, and ARM processors are affected (basically nearly every system). They are urging Intel to fix the problem and to offer those affected compensation for any losses that have occurred.

Intel also played down concerns about slowed performance because of the updates, noting that for the "average computer user", the impact should not be significant and will lessen over time. AMD claims that their processors have a near "zero risk" of exploitation, except one variant of the exploits, which can be resolved with an update.

Microsoft said in a statement Wednesday that it had updated "the majority" of its Azure cloud infrastructure, though some aspects "are still being updated and require a reboot of customer [virtual machines] for the security update to take effect".

Now, the California tech giant has confirmed that it has released mitigations for macOS and iOS as well as Safari on the App Store.

Recommended News

  • Acer's affordable gaming laptop gets a Ryzen processor and GPU boost

    Acer's affordable gaming laptop gets a Ryzen processor and GPU boost

    RAM and SSD storage are configurable up to 32GB and 512GB, respectively, with a 15.6-inch 1080p panel rounding out the computer. Acer's Swift 7 is the device in question, which was unveiled in Las Vegas a couple of days before CES 2018 actually kicked off.

    Syrian army claims Israel struck targets near Damascus in overnight raids

    As the conflict comes to an end that is bound to be messy, Israel wants to be a leading player in shaping its final outcome. It noted that the Israelis used surface-to-surface missiles and warplanes carry out strikes against Syrian soil.
    Toyota e-Palette Concept Vehicle debuts at 2018 CES

    Toyota e-Palette Concept Vehicle debuts at 2018 CES

    Toyota plans to begin testing the e-Palette concept in various regions, including the United States , in 2020. Toyota will design the vehicle with input from companies like Amazon, Didi, Mazda, Pizza Hut, and Uber.
  • Black Panther figurine headed to India

    Black Panther figurine headed to India

    If presale tickets are any indication, Marvel's latest superhero film could be in for a big opening. No concrete numbers for Black Panther or previous Marvel movies were released.
    Serena Williams Reveals the Story Behind Her Dramatic Baby Delivery

    Serena Williams Reveals the Story Behind Her Dramatic Baby Delivery

    When they did the surgery, they found a large hematoma had flooded her abdomen, and they would have to perform ANOTHER surgery. The 36-year-old first-time mom confessed that she'd had "an enviably easy pregnancy " until her scary labor experience.
    China May Stop Buying US Treasuries

    China May Stop Buying US Treasuries

    In reaction, as of 1256 GMT the yield on the benchmark 10-year US Treasury note was moving higher by four basis points to 2.59%. China's State Administration of Foreign Exchange didn't immediately reply to a fax seeking comment on the matter.
  • May slams Corbyn over 'too weak to sack Hunt' claims

    May slams Corbyn over 'too weak to sack Hunt' claims

    The NHS dominated the pair's exchanges at the first Prime Minister's Questions of 2018. And she told MPs: "This Government is putting more money into the NHS".
    Pokemon GO Ending Support for More iPhones and iPads

    Pokemon GO Ending Support for More iPhones and iPads

    Affected devices include the iPhone 5, iPhone 5c, iPad (4th generation), iPad (3rd generation), iPad mini, and iPad 2. For more info, and if you want to see if your device is affected, visit this link and find out more .
    Supreme Court to look at Ohio's voter-removal laws

    Supreme Court to look at Ohio's voter-removal laws

    Election law fights are long-game where incremental gains that favor one party are not often seen until years after courts rule. But that's what partisan Republicans do. "It has the shortest timeline for removing people for non-voting", Naifeh said.
  • Advantus Capital Management Inc Has $2409000 Position in Southwest Airlines Co. (LUV)

    It turned negative, as 65 investors sold JPM shares while 767 reduced holdings. 52 funds opened positions while 125 raised stakes. It has outperformed by 20.93% the S&P500. (GOOGL) by 1.95% based on its latest 2017Q3 regulatory filing with the SEC.
    Weather warning issued for widespread fog across Portsmouth area

    Weather warning issued for widespread fog across Portsmouth area

    There is a risk of icy stretches too, as it will turn frosty with slack winds as temperatures drop to a low of -1. The alert is in place from 4 o'clock this afternoon and remains in place until 4 o'clock tomorrow morning.
    Villas-Boas withdraws from Dakar Rally after being hospitalised

    Villas-Boas withdraws from Dakar Rally after being hospitalised

    Villas-Boas was driving a Toyota Hilux which was co-driven by former motorcycle class frontrunner Ruben Faria . The route is largely comprised of sand dunes, before moving to Bolivia and ending in Argentina on January 20.

We are pleased to provide this opportunity to share information, experiences and observations about what's in the news.
Some of the comments may be reprinted elsewhere in the site or in the newspaper.
Thank you for taking the time to offer your thoughts.