NZ Herald
  • Home
  • Latest news
  • Herald NOW
  • Video
  • New Zealand
  • Sport
  • World
  • Business
  • Entertainment
  • Podcasts
  • Quizzes
  • Opinion
  • Lifestyle
  • Travel
  • Viva
  • Weather

Subscriptions

  • Herald Premium
  • Viva Premium
  • The Listener
  • BusinessDesk

Sections

  • Latest news
  • New Zealand
    • All New Zealand
    • Crime
    • Politics
    • Education
    • Open Justice
    • Scam Update
  • Herald NOW
  • On The Up
  • World
    • All World
    • Australia
    • Asia
    • UK
    • United States
    • Middle East
    • Europe
    • Pacific
  • Business
    • All Business
    • MarketsSharesCurrencyCommoditiesStock TakesCrypto
    • Markets with Madison
    • Media Insider
    • Business analysis
    • Personal financeKiwiSaverInterest ratesTaxInvestment
    • EconomyInflationGDPOfficial cash rateEmployment
    • Small business
    • Business reportsMood of the BoardroomProject AucklandSustainable business and financeCapital markets reportAgribusiness reportInfrastructure reportDynamic business
    • Deloitte Top 200 Awards
    • CompaniesAged CareAgribusinessAirlinesBanking and financeConstructionEnergyFreight and logisticsHealthcareManufacturingMedia and MarketingRetailTelecommunicationsTourism
  • Opinion
    • All Opinion
    • Analysis
    • Editorials
    • Business analysis
    • Premium opinion
    • Letters to the editor
  • Politics
  • Sport
    • All Sport
    • OlympicsParalympics
    • RugbySuper RugbyNPCAll BlacksBlack FernsRugby sevensSchool rugby
    • CricketBlack CapsWhite Ferns
    • Racing
    • NetballSilver Ferns
    • LeagueWarriorsNRL
    • FootballWellington PhoenixAuckland FCAll WhitesFootball FernsEnglish Premier League
    • GolfNZ Open
    • MotorsportFormula 1
    • Boxing
    • UFC
    • BasketballNBABreakersTall BlacksTall Ferns
    • Tennis
    • Cycling
    • Athletics
    • SailingAmerica's CupSailGP
    • Rowing
  • Lifestyle
    • All Lifestyle
    • Viva - Food, fashion & beauty
    • Society Insider
    • Royals
    • Sex & relationships
    • Food & drinkRecipesRecipe collectionsRestaurant reviewsRestaurant bookings
    • Health & wellbeing
    • Fashion & beauty
    • Pets & animals
    • The Selection - Shop the trendsShop fashionShop beautyShop entertainmentShop giftsShop home & living
    • Milford's Investing Place
  • Entertainment
    • All Entertainment
    • TV
    • MoviesMovie reviews
    • MusicMusic reviews
    • BooksBook reviews
    • Culture
    • ReviewsBook reviewsMovie reviewsMusic reviewsRestaurant reviews
  • Travel
    • All Travel
    • News
    • New ZealandNorthlandAucklandWellingtonCanterburyOtago / QueenstownNelson-TasmanBest NZ beaches
    • International travelAustraliaPacific IslandsEuropeUKUSAAfricaAsia
    • Rail holidays
    • Cruise holidays
    • Ski holidays
    • Luxury travel
    • Adventure travel
  • Kāhu Māori news
  • Environment
    • All Environment
    • Our Green Future
  • Talanoa Pacific news
  • Property
    • All Property
    • Property Insider
    • Interest rates tracker
    • Residential property listings
    • Commercial property listings
  • Health
  • Technology
    • All Technology
    • AI
    • Social media
  • Rural
    • All Rural
    • Dairy farming
    • Sheep & beef farming
    • Horticulture
    • Animal health
    • Rural business
    • Rural life
    • Rural technology
    • Opinion
    • Audio & podcasts
  • Weather forecasts
    • All Weather forecasts
    • Kaitaia
    • Whangārei
    • Dargaville
    • Auckland
    • Thames
    • Tauranga
    • Hamilton
    • Whakatāne
    • Rotorua
    • Tokoroa
    • Te Kuiti
    • Taumaranui
    • Taupō
    • Gisborne
    • New Plymouth
    • Napier
    • Hastings
    • Dannevirke
    • Whanganui
    • Palmerston North
    • Levin
    • Paraparaumu
    • Masterton
    • Wellington
    • Motueka
    • Nelson
    • Blenheim
    • Westport
    • Reefton
    • Kaikōura
    • Greymouth
    • Hokitika
    • Christchurch
    • Ashburton
    • Timaru
    • Wānaka
    • Oamaru
    • Queenstown
    • Dunedin
    • Gore
    • Invercargill
  • Meet the journalists
  • Promotions & competitions
  • OneRoof property listings
  • Driven car news

Puzzles & Quizzes

  • Puzzles
    • All Puzzles
    • Sudoku
    • Code Cracker
    • Crosswords
    • Cryptic crossword
    • Wordsearch
  • Quizzes
    • All Quizzes
    • Morning quiz
    • Afternoon quiz
    • Sports quiz

Regions

  • Northland
    • All Northland
    • Far North
    • Kaitaia
    • Kerikeri
    • Kaikohe
    • Bay of Islands
    • Whangarei
    • Dargaville
    • Kaipara
    • Mangawhai
  • Auckland
  • Waikato
    • All Waikato
    • Hamilton
    • Coromandel & Hauraki
    • Matamata & Piako
    • Cambridge
    • Te Awamutu
    • Tokoroa & South Waikato
    • Taupō & Tūrangi
  • Bay of Plenty
    • All Bay of Plenty
    • Katikati
    • Tauranga
    • Mount Maunganui
    • Pāpāmoa
    • Te Puke
    • Whakatāne
  • Rotorua
  • Hawke's Bay
    • All Hawke's Bay
    • Napier
    • Hastings
    • Havelock North
    • Central Hawke's Bay
    • Wairoa
  • Taranaki
    • All Taranaki
    • Stratford
    • New Plymouth
    • Hāwera
  • Manawatū - Whanganui
    • All Manawatū - Whanganui
    • Whanganui
    • Palmerston North
    • Manawatū
    • Tararua
    • Horowhenua
  • Wellington
    • All Wellington
    • Kapiti
    • Wairarapa
    • Upper Hutt
    • Lower Hutt
  • Nelson & Tasman
    • All Nelson & Tasman
    • Motueka
    • Nelson
    • Tasman
  • Marlborough
  • West Coast
  • Canterbury
    • All Canterbury
    • Kaikōura
    • Christchurch
    • Ashburton
    • Timaru
  • Otago
    • All Otago
    • Oamaru
    • Dunedin
    • Balclutha
    • Alexandra
    • Queenstown
    • Wanaka
  • Southland
    • All Southland
    • Invercargill
    • Gore
    • Stewart Island
  • Gisborne

Media

  • Video
    • All Video
    • NZ news video
    • Herald NOW
    • Business news video
    • Politics news video
    • Sport video
    • World news video
    • Lifestyle video
    • Entertainment video
    • Travel video
    • Markets with Madison
    • Kea Kids news
  • Podcasts
    • All Podcasts
    • The Front Page
    • On the Tiles
    • Ask me Anything
    • The Little Things
  • Cartoons
  • Photo galleries
  • Today's Paper - E-editions
  • Photo sales
  • Classifieds

NZME Network

  • Advertise with NZME
  • OneRoof
  • Driven Car Guide
  • BusinessDesk
  • Newstalk ZB
  • Sunlive
  • ZM
  • The Hits
  • Coast
  • Radio Hauraki
  • The Alternative Commentary Collective
  • Gold
  • Flava
  • iHeart Radio
  • Hokonui
  • Radio Wanaka
  • iHeartCountry New Zealand
  • Restaurant Hub
  • NZME Events

SubscribeSign In
Advertisement
Advertise with NZME.
Home / Business

Apple reveals all iPhones, iPads and Macs are at risk from devastating Intel and ARM chip 'design flaws'

Daily Mail
5 Jan, 2018 04:35 PM11 mins to read

Subscribe to listen

Access to Herald Premium articles require a Premium subscription. Subscribe now to listen.
Already a subscriber?  Sign in here

Listening to articles is free for open-access content—explore other articles or learn more about text-to-speech.
‌
Save

    Share this article

Macs, iPhones, iPads and Apple TV all hit by the weakness according to Apple. Photo / Getty Images

Macs, iPhones, iPads and Apple TV all hit by the weakness according to Apple. Photo / Getty Images

Every iPhone, iPad and Mac device could be at risk of being hacked.

Apple has confirmed that almost all of its devices are affected by Intel and Arm chip "design flaws" that could expose billions of people's personal data to cyber criminals, the Daily Mail reported.

The flaws leave the devices open to the devastating Meltdown and Spectre bugs, discovered by security researchers.

The tech company has warned its customers to only download software for its platforms from trusted sources, like the App Store.

Apple says it has already put measures in place to help protect its customers from Meltdown and more will be released in the coming days.

Advertisement
Advertise with NZME.
Advertisement
Advertise with NZME.

The firm plans to release further measures for its Safari web browser to help defend against Spectre.

Browser makers Google, Microsoft Corp and Mozilla Corp's Firefox all confirmed to Reuters that the patches they currently have in place do not protect iOS users.

With Safari and virtually all other popular browsers not patched, hundreds of millions of iPhone and iPad users may have no secure means of browsing the web until Apple issues its patch.

Advertisement
Advertise with NZME.

Apple stressed that there were no known instances of hackers taking advantage of the flaw to date.

In a written statement, Apple said: "All Mac systems and iOS devices are affected, but there are no known exploits impacting customers at this time.

"Since exploiting many of these issues requires a malicious app to be loaded on your Mac or iOS device, we recommend downloading software only from trusted sources such as the App Store.

"We continue to develop and test further mitigations for these issues and will release them in upcoming updates of iOS, macOS, tvOS, and watchOS."

Discover more

Business

How Google saved $5.1 billion in taxes

03 Jan 03:43 AM
Business

iPhone XL coming in 2018 - report

04 Jan 02:35 AM
Employment

Is this nanny ad going too far?

04 Jan 04:54 AM
Companies

Spotify to show whether investors believe in music's resurgence

04 Jan 10:08 PM

Tech firms have been aware of the bugs since last year, with chip manufacturer Intel informed in June 2017, but the finds have only just gone public.

Apple remained silent for more than a day about the fate of the hundreds of millions of users of its products.

Ben Johnson, co-founder and chief strategist for cyber security firm Carbon Black, said the delay in updating customers about whether Apple's devices are at risk could affect Apple's drive to get more business customers to adopt its hardware.

Speaking to Reuters, he said: "Something this severe gets the attention of all the employees and executives at a company, and when they go asking the IT and security people about it and security doesn't have an answer for iPhones and iPads, it just doesn't give a whole lot of confidence."

'Spectre' affects chips in smartphones and tablets, as well as computer chips from Intel and Advanced Micro Devices Inc. Photo / File
'Spectre' affects chips in smartphones and tablets, as well as computer chips from Intel and Advanced Micro Devices Inc. Photo / File

Measures released in iOS 11.2, macOS 10.13.2, and tvOS 11.2 will to help defend against Meltdown, according to Apple.

Apple Watch is not affected by the issue.

Advertisement
Advertise with NZME.

Benchmark tests taken in December showed that the updates had no effect on performance, a spokesman for Cupertino-based company said.

These are expected to cause system slowdowns of around 2.5 per cent.

Security researchers at Google's Project Zero computer security analysis team, in conjunction with academic and industry researchers from several countries, exposed the two flaws this week.

Meltdown, which is specific to Intel chips, lets hackers bypass the hardware barrier between applications run by users and the computer's memory, potentially letting hackers read a computer's memory.

It was first discovered by Project Zero in June last year, when expert Jann Horn found that passwords, encryption keys, and sensitive information open in applications that should have been protected could be accessed.

A second bug, called Spectre, affects chips from Intel, AMD and Arm.

Advertisement
Advertise with NZME.

This lets hackers potentially trick otherwise error-free applications into giving up secret information.

Project Zero disclosed the Meltdown vulnerability not long after Intel said it's working to patch it.

Intel says the average computer user won't experience significant slowdowns as it's fixed.

Tech companies typically withhold details about security problems until fixes are available, so that hackers don't have a roadmap to exploit the flaws.

Both Intel and Google said they were planning to disclose the issue next week, when fixes will be available.

But Intel was forced to come clean about the problem yesterday after news of the flaw became public.

Advertisement
Advertise with NZME.

In an interview with CNBC yesterday, Intel CEO Brian Krzanich said: "We've found no instances of anybody actually executing this exploit.

"Phones, PCs, everything are going to have some impact, but it'll vary from product to product."

However, clips on social media claim to show computer security experts using the exploit.

Michael Schwarz, who has a PhD in information security, posted on Twitter "Using #Meltdown to steal passwords in real time", along with a GIF animation of the procedure.

Researchers say Apple and Microsoft have patches ready for users for desktop computers affected by Meltdown.

Microsoft declined to comment and Apple did not immediately return requests for comment.

Advertisement
Advertise with NZME.

Daniel Gruss, one of the researchers at Graz University of Technology who discovered Meltdown, called it "probably one of the worst CPU bugs ever found" in an interview with Reuters.

Gruss said Meltdown was the more serious problem in the short term but could be decisively stopped with software patches.

Spectre, the broader bug that applies to nearly all computing devices, is harder for hackers to take advantage of but less easily patched and will be a bigger problem in the long term, he said.

Intel's CEO said Google researchers told Intel of the flaws "a while ago" and that Intel had been testing fixes that device makers who use its chips will push out next week.

Before the problems became public, Google on its blog said Intel and others planned to disclose the issues on January 9.

Google said it informed the affected companies about the Spectre flaw on June 1, 2017 and reported the Meltdown flaw after the first flaw but before July 28, 2017.

Advertisement
Advertise with NZME.

The flaws were first reported by tech publication The Register.

It also reported that the updates to fix the problems could causes Intel chips to operate five to 30 per cent more slowly, with some experts claiming this could be more like 50 per cent.

Intel denied that the patches would bog down computers based on Intel chips.

"Intel has begun providing software and firmware updates to mitigate these exploits," the Santa Clara, California, Company said in a statement.

"Contrary to some reports, any performance impacts are workload-dependent, and, for the average computer user, should not be significant and will be mitigated over time."

ARM spokesman Phil Hughes said that patches had already been shared with the companies' partners, which include many smartphone manufacturers.

Advertisement
Advertise with NZME.

"This method only works if a certain type of malicious code is already running on a device and could at worst result in small pieces of data being accessed from privileged memory," Mr Hughes said in an email.

AMD chips are also affected by at least one variant of a set of security flaws but that it can be patched with a software update.

The company said it believes there "is near zero risk to AMD products at this time."

Google said in a blog post that Android phones running the latest security updates are protected, as are its own Nexus and Pixel phones with the latest security updates.

Gmail users do not need to take any additional action to protect themselves, but users of its Chromebooks, Chrome web browser and many of its Google Cloud services will need to install updates.

Amazon Web Services, a cloud computing service used by businesses, said that most of its internet servers were already patched and the rest were in the process of being patched.

Advertisement
Advertise with NZME.

The defect affects the so-called kernel memory on Intel x86 processor chips manufactured over the past decade, The Register reported citing unnamed programmers, allowing users of normal applications to discern the layout or content of protected areas on the chips.

That could make it possible for hackers to exploit other security bugs or, worse, expose secure information such as passwords, thus compromising individual computers or even entire server networks.

Dan Guido, chief executive of cyber security consulting firm Trail of Bits, said that businesses should quickly move to update vulnerable systems, saying he expects hackers to quickly develop code they can use to launch attacks that exploit the vulnerabilities.

"Exploits for these bugs will be added to hacker's standard toolkits," Mr Guido said.

Shares in Intel were down by 3.4 per cent following the report but nudged back up 1.2 per cent to US$44.70 in after-hours trading.

Shares in AMD were up one per cent to US$11.77, shedding many of the gains they had made earlier in the day when reports suggested its chips were not affected.

Advertisement
Advertise with NZME.

It was not immediately clear whether Intel would face any significant financial liability arising from the reported flaw.

"The current Intel problem, if true, would likely not require CPU replacement in our opinion. However the situation is fluid," Hans Mosesmann of Rosenblatt Securities in New York said in a note, adding it could hurt the company's reputation.

Apple remained silent for more than a day about the fate of the hundreds of millions of users of its products. Photo / Getty Images
Apple remained silent for more than a day about the fate of the hundreds of millions of users of its products. Photo / Getty Images

MELTDOWN AND SPECTRE: WHAT YOU NEED TO KNOW

Researchers from Google, academia and cybersecurity firms discovered two flaws in computer chips that affect nearly all modern computers:

Meltdown

This is a flaw that affects laptops, desktop computers and internet servers with Intel chips.

It lets hackers bypass the hardware barrier between applications run by users and the computer's kernel memory.

Advertisement
Advertise with NZME.

This has the potential to let hackers access the content of this portion of a computer's memory.

This would enable them to steal data, such as passwords saved in web browsers.

Spectre

This bug affects chips from Intel, AMD and ARM and lets hackers potentially trick otherwise error-free applications into giving up secret information.

'Spectre' affects chips in smartphones and tablets, as well as computer chips from Intel and Advanced Micro Devices Inc.

Hackers can trick apps into leaking sensitive information.

Advertisement
Advertise with NZME.

Spectre is a broader bug that applies to nearly all computing devices.

It is harder for hackers to take advantage of but less easily patched and will be a bigger problem in the long term, experts say.

HOW TO PROTECT YOURSELF

Intel - Chips from the past five years have been patched, more to come

The chip manufacturer says it has already issued updates for the majority of processor products introduced within the past five years.

By the end of next week, Intel expects to have issued updates for more than 90 per cent of processor products introduced within the past five years.

The firm is yet to announce a timetable for patching Intel processors more than five years old.

Advertisement
Advertise with NZME.

Reports have suggested that up to 15 years of Intel processors may be affected.

Google - Patch available today

On January 5, Google is issuing a security update to protect Android phones.

Google-branded phones should automatically download the update and you need to just install it. With Pixel and Pixel 2 the update will automatically install too.

Some Android phone manufacturers are slow to patch, so you should contact them to make sure they update it as soon as possible.

The patch for Chrome will be installed on January 23 and some Chromebooks had a mitigation in its OS 63, released in December, write Wired.

Advertisement
Advertise with NZME.

If don't want to wait until then an experimental feature from Google called Site Isolation can help in the meantime. This feature makes it harder for malicious websites to access data from other websites you are looking at, writes Cnet.

To use this feature on Windows, Mac, Linux, Chrome OS or Android copy and paste chrome://flags/#enable-site-per-process into the URL in Chrome. Click 'Strict Site Isolation' and then press 'Enable'.

Save your work and then press 'Relaunch now'.

A few Chromebooks are not expected to get the patch because they are too old. Here is a full list (look for 'no' in the right-hand column).

According to Google no other products are affected by these vulnerabilities.

Microsoft - Windows 10 patch available, older versions to come

Advertisement
Advertise with NZME.

There is already a patch available for Windows 10 which will automatically be applied.

For older operating systems a patch will be available next week. According to the company, Azure infrastructure is updated.

Linux - Patch available

The system has a patch.

Reports suggest it can slow down Linux-based systems by as much as 17 per cent. Users can opt out if they do not want it.

Amazon - Cloud services patched

Advertisement
Advertise with NZME.

The company says its web services have been updated.

Major cloud services aimed at business customers, including Amazon Web Services, Google Cloud Platform and Microsoft Azure, say they have already patched most of their services

Consumers should check with their device maker and operating system provider for security updates and install them as soon as possible.

Save

    Share this article

Latest from Business

Premium
Shares

Market close: Geopolitical tensions keep NZ market flat, US Fed decision looms

18 Jun 06:09 AM
Premium
Business

Fringe Benefit Tax: Should you be paying it if your business owns a ute?

18 Jun 06:00 AM
New Zealand

'Life-changing': International flights return to Hamilton Airport

18 Jun 05:23 AM

Audi offers a sporty spin on city driving with the A3 Sportback and S3 Sportback

sponsored
Advertisement
Advertise with NZME.

Latest from Business

Premium
Market close: Geopolitical tensions keep NZ market flat, US Fed decision looms

Market close: Geopolitical tensions keep NZ market flat, US Fed decision looms

18 Jun 06:09 AM

The S&P/NZX 50 Index closed down 0.10%, falling to 12,627.32.

Premium
Fringe Benefit Tax: Should you be paying it if your business owns a ute?

Fringe Benefit Tax: Should you be paying it if your business owns a ute?

18 Jun 06:00 AM
'Life-changing': International flights return to Hamilton Airport

'Life-changing': International flights return to Hamilton Airport

18 Jun 05:23 AM
Premium
Liam Dann: 'Brick wall' – why tomorrow’s GDP data won’t tell the real story

Liam Dann: 'Brick wall' – why tomorrow’s GDP data won’t tell the real story

18 Jun 05:17 AM
Gold demand soars amid global turmoil
sponsored

Gold demand soars amid global turmoil

NZ Herald
  • About NZ Herald
  • Meet the journalists
  • Newsletters
  • Classifieds
  • Help & support
  • Contact us
  • House rules
  • Privacy Policy
  • Terms of use
  • Competition terms & conditions
  • Our use of AI
Subscriber Services
  • NZ Herald e-editions
  • Daily puzzles & quizzes
  • Manage your digital subscription
  • Manage your print subscription
  • Subscribe to the NZ Herald newspaper
  • Subscribe to Herald Premium
  • Gift a subscription
  • Subscriber FAQs
  • Subscription terms & conditions
  • Promotions and subscriber benefits
NZME Network
  • The New Zealand Herald
  • The Northland Age
  • The Northern Advocate
  • Waikato Herald
  • Bay of Plenty Times
  • Rotorua Daily Post
  • Hawke's Bay Today
  • Whanganui Chronicle
  • Viva
  • NZ Listener
  • Newstalk ZB
  • BusinessDesk
  • OneRoof
  • Driven Car Guide
  • iHeart Radio
  • Restaurant Hub
NZME
  • About NZME
  • NZME careers
  • Advertise with NZME
  • Digital self-service advertising
  • Book your classified ad
  • Photo sales
  • NZME Events
  • © Copyright 2025 NZME Publishing Limited
TOP