A vulnerability on most chips in the market has been discovered last week, including the Spectre Meltdown issues. To-date, flaws are known to be affecting Intel, Apple, Qualcomm, AMD and majority of chips currently in the market. As Kaspersky explains, ” The first vulnerability, Meltdown can effectively remove the barrier between user applications and the sensitive parts of the operating system. The second vulnerability, Spectre, also found in AMD and ARM chips can trick vulnerable applications into leaking their memory contents.”

Kaspersky’s statement by Ido Naor, Senior Security Researcher, GReAT and Jornt van der Wiel, Senior Security Researcher GReAT explained the attack and how it puts users at risk:
“Applications installed on a device generally run on ‘user mode’, away from the more sensitive parts of the operating system. If an app needs access to a sensitive area, for example the underlying disc, network or processing unit, it needs to ask permission to use ‘protected mode’. In Meltdown’s case, an attacker could access protected mode and the core memory without requiring permission, effectively removing the barrier – and enabling them to potentially steal data from the memory of running apps, such as data from password managers, browsers, emails, and photos and documents.
“As they are hardware bugs, patching is a significant job. Patches against Meltdown have been issued for Linux, Windows and OS X, and work is underway to strengthen software against future exploitation of Spectre. Intel has a tool you can use to check if your system is vulnerable to the bugs and Google has published further information here. It is vital that users install any available patches without delay. It will take time for attackers to figure out how to exploit the vulnerabilities – providing a small but critical window for protection.”
During CES Tech Day, CTO of AMD, Mark Papermaster, addressed the Spectre Meltdown issue during his keynote speech. He comments that AMD “will remain vigilant, it is our utmost priority”.
Below is AMD’s breakdown on the effects of Spectre and Meltdown, on AMD processors.
Spectre
Variant 1: Bound Check Bypass: resolved by software/os update being made available by vendors /manufacturers.
Variant 2: Branch Target Injection: differences in AMD architecture mean there is a near zero risk and vulnerability to variant 2 has not been demonstrated on AMD processors to date.
Meltdown
Variant 3: Rogue Data Cache Load (not affecting AMD): zero AMD vulnerability or risk because of AMD architecture differences.



