Apple Confirms 'Meltdown' and 'Spectre' Vulnerabilities Impact All Macs and iOS Devices, Some Fixes Already Released [Updated]

Apple today confirmed that it has addressed the recent "Meltdown" vulnerability in previously released iOS 11.2, macOS 10.13.2, and tvOS 11.2 updates, with additional fixes coming to Safari in the near future to defend against the "Spectre" vulnerability.

12 inch macbook macbook pro duo
Apple has also confirmed that the two vulnerabilities affect all Mac and iOS devices. The company's full statement, available through a new support document covering Meltdown and Spectre, is below:

Security researchers have recently uncovered security issues known by two names, Meltdown and Spectre. These issues apply to all modern processors and affect nearly all computing devices and operating systems.

All Mac systems and iOS devices are affected, but there are no known exploits impacting customers at this time. Since exploiting many of these issues requires a malicious app to be loaded on your Mac or iOS device, we recommend downloading software only from trusted sources such as the App Store.

Apple has already released mitigations in iOS 11.2, macOS 10.13.2, and tvOS 11.2 to help defend against Meltdown. Apple Watch is not affected by Meltdown. In the coming days we plan to release mitigations in Safari to help defend against Spectre. We continue to develop and test further mitigations for these issues and will release them in upcoming updates of iOS, macOS, tvOS, and watchOS.

Apple's statement does not make it clear if these vulnerabilities have been addressed in older versions of iOS and Mac, but for Macs, there were security updates for older versions of macOS released alongside macOS 10.13.2, so it's possible fixes are already available for Sierra and El Capitan.

News of the Spectre and Meltdown vulnerabilities first came to light this week, but Intel and major operating system vendors like Apple, Linux, and Microsoft have known about the issue for several months and worked to prepare a fix before the security flaws were publicly shared.

Spectre and Meltdown are serious vulnerabilities that take advantage of the speculative execution mechanism of a CPU. As these use hardware-based flaws, operating system manufacturers are required to implement software workarounds. These software workarounds can impact processor performance, but Intel has insisted most users will not see serious slowdowns. Apple also says that no measurable impact has been detected in macOS and iOS.

Apple released mitigations for Meltdown in iOS 11.2, macOS 10.13.2, and tvOS 11.2. watchOS did not require mitigation. Our testing with public benchmarks has shown that the changes in the December 2017 updates resulted in no measurable reduction in the performance of macOS and iOS as measured by the GeekBench 4 benchmark, or in common Web browsing benchmarks such as Speedometer, JetStream, and ARES-6.

The Meltdown vulnerability allows a malicious program to read kernel memory, accessing data like passwords, emails, documents, photos, and more. Meltdown can be exploited to read the entire physical memory of a target machine. The vulnerability is particularly problematic for cloud-based services.

Spectre, which covers two exploitation techniques, breaks the isolation between different applications. Apple says that while the Spectre vulnerability is difficult to exploit, it can be done using JavaScript in a web browser. Apple plans to release Safari updates for macOS and iOS to prevent Spectre-based exploits.

As with the Meltdown vulnerability, Apple says the upcoming Safari mitigations will have "no measurable impact" on Speedometer and ARES-6 tests, and an impact of less than 2.5% on the JetStream benchmark.

Apple says it will continue to test further mitigations for Spectre and will release them in future versions of iOS, macOS, tvOS, and watchOS.

Update: Apple has updated its Meltdown and Spectre support document to clarify that the Apple Watch is not affected by either vulnerability. Previously, Apple had only confirmed that the Apple Watch was unaffected by Meltdown.

Update 2: Apple has confirmed that fixes have also been released for macOS Sierra and OS X El Capitan in an updated security support document.

Update 3: The support document that confirmed the fixes for Sierra and El Capitan has been updated again to remove references to these two operating systems, so it remains unclear whether or not Meltdown fixes have been released for these two older operating systems.

Popular Stories

iCloud General Feature Redux

iPhone Users Who Pay for iCloud Storage Receive a New Perk

Thursday March 20, 2025 12:01 am PDT by
If you pay for iCloud storage on your iPhone, Apple has a new perk for you, at no additional cost. The new perk is the ability to create invitations in the Apple Invites app for the iPhone, which launched in the App Store last month. In the Apple Invites app, iCloud+ subscribers can create invitations for any occasion, such as birthday parties, graduations, baby showers, and more. Anyone ...
Generic iOS 19 Feature Mock

iOS 19 Coming in June With These New Features

Thursday March 20, 2025 2:04 pm PDT by
While the first iOS 19 beta is still more than two months away, there are already plenty of rumors about the upcoming software update. Below, we recap the key iOS 19 rumors so far. visionOS-Like Design In January, the YouTube channel Front Page Tech revealed a redesigned Camera app that is allegedly planned for iOS 19. According to Front Page Tech host Jon Prosser, the Camera app...
apple wallet drivers license feature iPhone 15 pro teal 1

Apple Says iPhone Driver's Licenses Coming to These 8 U.S. States, But Rollout Remains Slow

Wednesday March 19, 2025 6:55 am PDT by
In select U.S. states, residents can add their driver's license or state ID to the Wallet app on the iPhone and Apple Watch, providing a convenient and contactless way to display proof of identity or age at select airports and businesses, and in select apps. Unfortunately, this feature continues to roll out very slowly. It has been three and a half years since Apple first announced the...
Windows Vista

Apple Might Be Having Its Windows Vista Moment, Says Analyst

Thursday March 20, 2025 6:52 am PDT by
Is Apple experiencing a "Vista-like drift into systemically poor execution?" That was a question posed by well-known technology analyst Benedict Evans, in a recent blog post covering Apple's innovation and execution, or seemingly lack thereof as of late. He is referring to Microsoft's Windows Vista operating system, which was widely criticized when it launched in 2007 due to software bugs,...
iPhone 17 Pro Render Front Page Tech

Latest iPhone 17 Pro Dummies Highlight Apple's New Part-Glass Design

Thursday March 20, 2025 5:27 am PDT by
Seasoned leaker Sonny Dickson has shared more dummy models of Apple's upcoming iPhone 17 series, with the latest lot revealing a noticeable shift in Apple's iPhone Pro model design that goes beyond the much-talked-about new rear camera bar. Dickson points out that the iPhone 17 Pro dummy models feature an outlined area on the back, beginning just below the camera module and extending to the...
iOS 18

Top 5 New Features Coming in iOS 18.4

Friday March 21, 2025 3:26 pm PDT by
We're not getting new Siri Apple Intelligence features in iOS 18.4 as expected, but the upcoming update does have quite a few new additions that will be worth upgrading for. We've rounded up the five best features to look forward to, and if you're not running the beta, you can expect to get access to these in early April. Priority Notifications If you have an iPhone or iPad that supports...
airtag orange

Apple's Next Product is Likely an AirTag 2 With These New Features

Thursday March 20, 2025 2:30 pm PDT by
Following the introduction of the iPhone 16e, new iPads and Macs, and some new accessories over the past month, what will Apple's next product announcement be? Based on rumors, a second-generation AirTag item tracker is likely next up. Last year, Bloomberg's Mark Gurman reported that a new AirTag would be released around the middle of 2025. More recently, a leaker known as Kosutami claimed...
airpods pro 2 gradient

AirPods Pro 3 Launch Now Just Months Away: Here's What We Know

Tuesday March 18, 2025 9:13 am PDT by
Despite being released over two years ago, Apple's AirPods Pro 2 continue to dominate the wireless earbud market. However, with the AirPods Pro 3 expected to launch in 2025, anyone thinking of buying Apple's premium earbuds may be wondering if the next generation is worth holding out for. Apart from their audio and noise-canceling performance, which are generally regarded as excellent for...
iPhone 17 Air Fanned Feature

First iPhone 17 Air Case Has Camera Bar, Camera Control Button Cutouts

Wednesday March 19, 2025 5:29 am PDT by
Serial leaker Sonny Dickson today shared an image of what he claims is a first look at a third-party case for Apple's iPhone 17 Air. "If you didn’t know an Air was coming, you'd swear it was a Google Pixel case," he said. Case manufacturers often obtain design specifications of upcoming iPhone models before their release by collaborating with Apple through official partnerships or...

Top Rated Comments

bradl Avatar
94 months ago
The question looming here is, will those MacOS patches be backported to Sierra down to Mavericks, or even if supported, Mountain Lion? We already know that previous versions of iOS and tvOS are not going to have this patch, so they're stuck.. but what of MacOS?

BL.
Score: 26 Votes (Like | Disagree)
OldSchoolMacGuy Avatar
94 months ago
That was quick. And yet there were still many crying "Why won't Apple be more open and talk about this!!!!"
Score: 22 Votes (Like | Disagree)
bradl Avatar
94 months ago
Does it only affect Intel processors?
Spectre affects all modern processors, including those designed by Intel, AMD and ARM, but Meltdown is currently thought only to affect Intel ('https://www.theguardian.com/technology/intel') chips manufactured since 1995, with the exception of the Itanium and Atom chips made before 2013.

https://www.theguardian.com/technology/2018/jan/04/meltdown-spectre-computer-processor-intel-security-flaws-explainer
Guess I'm busting back out my 486SX20 (without the math coprocessor), and dropping back to 32bit Linux and Windows 3.1.

Doom, Duke Nukem, and Leisure Suit Larry, here I come! :D :P

BL.
Score: 14 Votes (Like | Disagree)
OldSchoolMacGuy Avatar
94 months ago
Great to hear that there was some proactive action taken quickly against these vulnerabilities. And glad to see the flaws took the proper disclosure path rather than someone tweeting how to take advantage of the vulnerability for his/her 15 minutes of fame. ;)
Daniel Gruss, a information security researcher and post-doctoral fellow at Austria's Graz Technical University was the one that discovered Meltdown last year. Though now Google claims they too discovered it after that time. Seems like one of those, "Oh... uh.... yeah... we totally already knew about that but just didn't say anything. We're totally in the know.", on Google's part.
Score: 13 Votes (Like | Disagree)
SecuritySteve Avatar
94 months ago
The question looming here is, will those MacOS patches be backported to Sierra down to Mavericks, or even if supported, Mountain Lion? We already know that previous versions of iOS and tvOS are not going to have this patch, so they're stuck.. but what of MacOS?

BL.
Most likely the fixes will be back ported to Sierra and El Capitan alongside 10.13.3. It's not official policy, but Apple only releases security updates for the latest, and previous two OS's. Anything behind El Capitan is EOL by most software security scanners.
Score: 12 Votes (Like | Disagree)
JPack Avatar
94 months ago
Where are the Apple cheerleaders who were chastising Intel for this hardware flaw?

It's pretty clear Apple processors are affected as well. Where's chastising now for Apple?
Score: 11 Votes (Like | Disagree)