Reprinted from TidBITS by permission; reuse governed by Creative Commons license BY-NC-ND 3.0. TidBITS has offered years of thoughtful commentary on Apple and Internet topics. For free email subscriptions and access to the entire TidBITS archive, visit http://www.tidbits.com/ Apple Releases Information on Meltdown and Spectre Adam C. Engst The tech world has been abuzz with discussion of [1]Meltdown and Spectre, massive 'speculative execution' security vulnerabilities recently discovered in the CPUs used by nearly all modern computing devices, including the Intel CPUs used in Macs and the ARM-based CPUs in iOS devices. [2]Ars Technica has a good explanation of the problem and overview of the response from different companies. Apple has now posted a [3]support note explaining the situation from the company's perspective. In short, Apple released mitigations for Meltdown in iOS 11.2, macOS 10.13.2, and tvOS 11.2, and claims that its changes resulted in no measurable reduction in performance. An upcoming release of Safari will mitigate the Spectre exploits with only a minimal performance impact. Apple says that the Apple Watch is unaffected by both Meltdown and Spectre. That's all good, but note the word 'mitigate' in Apple's note ' the company isn't saying 'fix.' Spectre, in particular, is a subtle vulnerability, and we'll likely be seeing additional protections worked into software over time. In other words, staying up to date with the latest security fixes from Apple is becoming ever more important. References 1. https://meltdownattack.com/ 2. https://arstechnica.com/gadgets/2018/01/meltdown-and-spectre-heres-what-intel-apple-microsoft-others-are-doing-about-it/ 3. https://support.apple.com/en-us/HT208394 .