HomeWinBuzzer NewsNew Firefox Update Helps Mitigate Meltdown and Spectre CPU Exploits

New Firefox Update Helps Mitigate Meltdown and Spectre CPU Exploits

Firefox's latest update reduces the accuracy of time sources in the browser, making it much harder to perform web-based Spectre and Meltdown attacks. Google plans to follow with a patch on January 24.

-

Manufacturers, software creators and more have been rushing to protect users from vital flaws found in processors. Many chips from the last decade have ‘Meltdown and Spectre’ flaws that allow kernel access, from phones to laptops and tablets.

The flaws are embedded in the kernel operations within a system. When a command is sent to perform any task, the CPU passes control to the kernel, which stays below the surface in processes even once the CPU takes back control. This is to ensure smoother and faster performance, but also means systems are potentially at risk at kernel level.

Attackers can make use of JavaScript code in the browser to potentially read memory in a user’s machine. In a bid to help, browsers have also implemented security measures, including Mozilla’s Firefox. Version 57.0.4 introduces a workaround that should make its users safer.

The main change is an adjustment to the time sources in the browser, making them less precise.

“Since this new class of attacks involves measuring precise time intervals, as a partial, short-term, mitigation we are disabling or reducing the precision of several time sources in Firefox,” explained Mozilla. “This includes both explicit sources, like performance.now(), and implicit sources that allow building high-resolution timers, viz., SharedArrayBuffer.

However, Mozilla is also looking at more long-term solutions. It’s keeping the details close to its chest for now, but it involves removing the information leak closer to its source.

Google Chrome Patch Coming

Mozilla’s patch follows Microsoft’s, who implemented a very similar method in Edge and Internet Explorer, as well as changes to Windows. Chome, which makes up the majority of the browser market share, is yet to release a patch.

However, Google has revealed that a release is in the works. It will come with Chrome 64, which is set to release on January 24. In the meantime, users can enable Site Isolation, which isolates webpages into separate address spaces.

Even so, some believe that the only way to truly fix Spectre and Meltdown is hardware replacement, including CERT. If correct, it could become very expensive for chip makers.

Ryan Maskell
Ryan Maskellhttps://ryanmaskell.co.uk
Ryan has had a passion for gaming and technology since early childhood. Fusing the skills from his Creative Writing and Publishing degree with profound technical knowledge, he enjoys covering news about Microsoft. As an avid writer, he is also working on his debut novel.

Recent News

0 0 votes
Article Rating
Subscribe
Notify of
guest
0 Comments
Newest
Oldest Most Voted
Inline Feedbacks
View all comments
0
Would love your thoughts, please comment.x
()
x
Mastodon