Microsoft, Intel, and Google have jointly disclosed a new variant of the Meltdown and Spectre vulnerabilities that originally drew attention in January. So far, Intel says it hasn't yet seen any reports of the method being employed as part of "real-world exploits."
Dubbed "Variant 4," the new vulnerability uses speculative execution to expose data in a method similar to the original set of variants. The variant, Intel says, was demonstrated by researchers in a language-based runtime environment, which is commonly used in web browsers.
However, protections already deployed by browser makers for earlier variants also applicable to Variant 4. From Intel:
Starting in January, most leading browser providers deployed mitigations for Variant 1 in their managed runtimes – mitigations that substantially increase the difficulty of exploiting side channels in a web browser. These mitigations are also applicable to Variant 4 and available for consumers to use today.
Still, Intel says it is working on a combination of microcode and software updates that will provide further mitigation for Variant 4. The microcode updates are already available as a beta for OEM manufacturers and software vendors, and Intel expects them to be released "over the coming weeks." In its tests, Intel says it saw a performance impact of between two and eight percent with the mitigation enabled. However, once available, the mitigation will be off by default with the option to enable it.
In its own security advisory, Microsoft said: "At the time of publication, we are not aware of any exploitable code patterns of this vulnerability class in our software or cloud service infrastructure, but we are continuing to investigate."
Though it initially hit some snags with its first round of patches for the original exploits, Intel in March said it had released microcode updates for all of its products released in the past five years. Going forward, Intel is redesigning its processors to guard against attacks like Meltdown and Spectre.
We may earn a commission for purchases using our links. Learn more.
Everything Bethesda Softworks is working on right now for Xbox and PC
Microsoft stunned the gaming world when it announced it was acquiring ZeniMax Media, adding Bethesda Softworks to Xbox. Here's everything Bethesda Softworks is working on right now.
We go hands-on with the remastered Age of Empires III: Definitive Edition
Age of Empires III: Definitive Edition is expected to be released October 15, 2020, and we were able to get our hands on a preview build to see how it's coming along.
Dell's XPS 13 2-in-1 and XPS 15 are both beautiful, but which one is best?
These two laptops from Dell are similarly priced, but they have some significant differences that will sway you one way or the other in your buying process. We've laid out the stuff you need to know right here.
Use these motherboards with Intel's Core i5-10600K
Picking the best motherboard for the Intel Core i5-10600K processor is a relatively straightforward task as the best motherboard is one that ticks all your requirement boxes. We've rounded up a few recommendations to point you in the right direction.