Two newly disclosed CPU vulnerabilities threaten the security of devices around the world, but Google is here to tell you what to do to stay safe.
The Mountain View-based company explained on its security blog Wednesday that it has been aware of the risks posed by the “speculative execution” vulnerability for some time and is working to remediate potentially compromised systems.
“As soon as we learned of this new class of attack, our security and product development teams mobilized to defend Google’s systems and our user data,” Google explained in its post. “We have updated our systems and affected products to protect against this new type of attack.”
Someone who exploits this bug could theoretically steal passwords and other personal data from a computer. In other words, it's malicious.
It's important to note that Google's blog post seems to specifically address the vulnerability called Spectre and not necessarily Meltdown. Fortunately, though, there are fixes for Meltdown as well - Microsoft, for example, has already released one.
Google has carefully published a detailed list, noting “affected Google products and the current status of their response to speculative execution CPU attack methods.” It includes steps the company has already taken and provides suggestions for users of various products like Chrome (and you should probably heed the company’s security advice).
Some of the highlights are that up-to-date Android devices (because it also threatens mobile) are protected, as are fully updated and supported Nexus and Pixel devices. You also don't have to worry about Gmail or G Suite.
However, if you use the Google Cloud Platform, you may need to take some actions to protect yourself.
Either way, Google clearly wants you to know that even if everything is disorganized in the world of cybersecurity, it's still watching out for you.
