Microsoft just issued a fix for that big Intel processor vulnerability

Phew.
 By 
Jack Morse
 on 
Microsoft just issued a fix for that big Intel processor vulnerability
Fixing stuff. Credit: Stephen Brashear /Getty Images

So your computer is probably vulnerable to a processor chip bug that could theoretically let JavaScript running in a web browser steal your passwords (among other problems). Both your computer and your smartphone are at risk. It's not good.

Thankfully, however, for anyone with a machine running Windows, you're probably in the clear. That's because on Wednesday, January 3, Microsoft released a fix.

So reports ZDNet, which explains this patch was not issued on Microsoft's standard Patch Tuesday — suggesting someone at the company decided it was urgent. Importantly, a Microsoft support page notes that the fix only applies to devices running Windows 10.

According to Microsoft, the "update will be downloaded and installed automatically from Windows Update."

"We are in the process of deploying mitigations to cloud services and are releasing security updates today to protect Windows customers against vulnerabilities affecting supported hardware chips from AMD, ARM, and Intel," a Microsoft spokesperson explained in an emailed statement to Mashable. "We have not received any information to indicate that these vulnerabilities had been used to attack our customers.”

Apple, for its part, has also reportedly patched the vulnerability in macOS 10.13.2.

In the meantime, more information has dropped on what actually turns out to be two separate vulnerabilities in a wide range of processor chips (not just from Intel). Dubbed Meltdown and Spectre, the bugs differ in both the ease of exploit and ease of mitigation.

"Meltdown and Spectre exploit critical vulnerabilities in modern processors," explains a website dedicated to the findings. "These hardware bugs allow programs to steal data which is currently processed on the computer. While programs are typically not permitted to read data from other programs, a malicious program can exploit Meltdown and Spectre to get hold of secrets stored in the memory of other running programs. This might include your passwords stored in a password manager or browser, your personal photos, emails, instant messages and even business-critical documents."

Software patches exist for Meltdown, and security researchers are working on fixes for Spectre.

As always, your safest bet is to make sure you update your OS early and often to help mitigate the risk of known vulnerabilities.

This story has been updated to both include comment from Microsoft and note that the Microsoft patch only applies to devices running Windows 10.

Mashable Image
Jack Morse

Professionally paranoid. Covering privacy, security, and all things cryptocurrency and blockchain from San Francisco.

Mashable Potato

Recommended For You

Hackers are exploiting a vulnerability in lots of e-commerce sites
Fish-eye lens view of a computer screen with hacking stuff on it

MSI Prestige 14 Flip AI+ review: Intel Panther Lake arrives with a roar
the msi prestige 14 flip ai+ with its msi nano pen

Microsoft 365 Outlook down: Microsoft breaks silence on outage
Microsoft logo

Give your PC a big upgrade for a small price with this Microsoft bundle
The Ultimate Microsoft Office Professional 2021 for Windows: Lifetime License + Windows 11 Pro Bundle

More in Tech

Trending on Mashable
NYT Connections hints today: Clues, answers for April 3, 2026
Connections game on a smartphone

Wordle today: Answer, hints for April 3, 2026
Wordle game on a smartphone

NYT Connections hints today: Clues, answers for April 4, 2026
Connections game on a smartphone

Google launches Gemma 4, a new open-source model: How to try it
Google Gemma

Wordle today: Answer, hints for April 4, 2026
Wordle game on a smartphone
The biggest stories of the day delivered to your inbox.
These newsletters may contain advertising, deals, or affiliate links. By clicking Subscribe, you confirm you are 16+ and agree to our Terms of Use and Privacy Policy.
Thanks for signing up. See you at your inbox!