New Meltdown and Spectre exploits have been built, but aren’t in the wild… yet

Intel Core i9

We heard last month that white hat security researchers could be close to engineering a usable exploit for the Meltdown and Spectre vulnerabilities, and this has now actually happened.

Security experts from Nvidia and Princeton University have authored a new research paper which details ‘MeltdownPrime’ and ‘SpectrePrime’, exploits which leverage these gaping flaws in modern processors via side-channel timing attacks.

And these attacks can be used to prise out sensitive data from cache memory which could include the likes of passwords. As the Register reports, the SpectrePrime proof-of-concept exploit has already been successfully used on a MacBook with an Intel Core i7 processor, although the Meltdown variant (which is only applicable to Intel’s chips) hasn’t yet been successfully demonstrated on an actual real piece of hardware.

Before we get too carried away with the potential dangers here, it’s important to clarify that no code for these exploits has been released, so there’s no imminent risk. That said, if the good guys have cooked up a successful exploit, the bad guys out there may well be on the brink of doing so as well.

The other positive point is that the current patches underway for Meltdown and Spectre are likely to protect against these (and other potential) exploits. Of course, we’re still waiting for an official patch from Intel, with only Skylake machines having received a revamped Spectre patch (following stability issues with the previous fix) last week.

What’s more worrying, however, is that the researchers suggest that processor manufacturers might be in trouble when it comes to making hardware changes to try to guarantee immunity from these flaws going forward.

In other words, these issues are so deeply embedded in the silicon of contemporary processors, that getting rid of them completely – and covering all bases of all potential exploits therein – may be extremely difficult.

Intel has already said that chips which are resistant to Meltdown and Spectre will emerge later this year, whereas AMD is saying that it will be rolling out Spectre-proof processors in 2019 with its Zen 2 architecture. Let’s hope that those promises hold.

How to protect against Spectre and Meltdown

Meltdown and Spectre

For the latest on how to protect yourself from Spectre and Meltdown, read our comprehensive guide.

Bounty Bob

Meanwhile, Intel is taking further steps to battle against major security holes like these, updating its ‘bug bounty’ program, which pays out rewards to people who find and disclose vulnerabilities.

The scheme is now offering up to $250,000 (around £180,000, AU$315,000) for researchers who find side-channel vulnerabilities like Meltdown and Spectre, whereas the maximum bounty has been raised to $100,000 (around £70,000, AU$125,000) elsewhere.

Intel is also making the program available to all-comers, meaning that any security researcher can contribute, whereas previously this was an invite-only affair. That means more folks hunting for bugs, and hopefully finding them so Intel can patch them up in good time before disclosure happens.

That’s the theory anyway, but with gaping holes like Meltdown and Spectre, patching has still been a chaotic matter even though Intel was informed about these problems in June and July of last year.

TOPICS

Darren is a freelancer writing news and features for TechRadar (and occasionally T3) across a broad range of computing topics including CPUs, GPUs, various other hardware, VPNs, antivirus and more. He has written about tech for the best part of three decades, and writes books in his spare time (his debut novel - 'I Know What You Did Last Supper' - was published by Hachette UK in 2013).

Latest in Macbooks
Apple MacBook Air M3 on yellow background with lowest price text overlay
Forget the MacBook Air M4: here are 9 older-model MacBook deals from $629.99
MacBook Air mute key
The new M4 MacBook Air finally fixes an Apple keyboard annoyance that's been around for decades
The Apple MacBook Air M2 on a red background with text saying Lowest Price next to it.
The excellent MacBook Air M2 drops to an unbelievable price of $699 - yes, really
Collage of Apple tech on a pink background, including MacBook, iPad, AirPods and Apple Watch
Massive Apple sale live at Best Buy: get a MacBook Air for $699, Apple Watch for $299 and cheap AirPods
Apple MacBook Air M3
The M3 MacBook Air is officially discontinued, but the M2 MacBook Air will live on elsewhere and that's good news
13-inch and 15-inch MacBook Air M4 in Sky Blue
I saw Apple's new 13- and 15-inch MacBook Air with M4, and here's why Sky Blue is my new favorite color
Latest in News
Apple's Craig Federighi demonstrates the iPhone Mirroring feature of macOS Sequoia at the Worldwide Developers Conference (WWDC) 2024.
Report: iOS 19 and macOS 16 could mark their biggest design overhaul in years – and we have one request
Google Gemini Calendar
Gemini is coming to Google Calendar, here’s how it will work and how to try it now
Lego Mario Kart – Mario & Standard Kart set on a shelf.
Lego just celebrated Mario Day in the best way possible, with an incredible Mario Kart set that's up for preorder now
TCL QM7K TV on orange background
TCL’s big, bright new mid-range mini-LED TVs have built-in Bang & Olufsen sound
Apple iPhone 16e
Which affordable phone wins the mid-range race: the iPhone 16e, Nothing 3a, or Samsung Galaxy A56? Our latest podcast tells all
An image of a Jackbox Games Party Pack
Jackbox games is coming to smart TVs in mid-2025, and I can’t wait to be reunited with one of my favorite party video games