Apple Addresses Meltdown and Spectre in macOS Sierra and OS X El Capitan With New Security Update

Along with macOS High Sierra 10.13.3, Apple this morning released two new security updates that are designed to address the Meltdown and Spectre vulnerabilities on machines that continue to run macOS Sierra and OS X El Capitan.

As outlined in Apple's security support document, Security Update 2018-001 available for macOS Sierra 10.12.6 and OS X El Capitan 10.11.6 offers several mitigations for both Meltdown and Spectre, along with fixes for other security issues, and the updates should be installed immediately.

meltdownspectre
Apple addressed the Meltdown and Spectre vulnerabilities in macOS High Sierra with the release of macOS High Sierra 10.13.2, but older machines were left unprotected. Apple initially said a prior security update included fixes for the two older operating systems, but that information was later retracted.

Spectre and Meltdown are two hardware-based vulnerabilities that impact nearly all modern processors. Apple in early January confirmed that all of its Mac and iOS devices were impacted, but Meltdown mitigations were introduced ahead of when the vulnerabilities came to light in iOS 11.2 and macOS 10.13.2, and Spectre was addressed through Safari updates in iOS 11.2.2 and a macOS 10.13.2 Supplemental Update.

Spectre and Meltdown take advantage of the speculative execution mechanism of a CPU. As these use hardware-based flaws, operating system manufacturers are required to implement software workarounds. These software workarounds can impact processor performance, but according to Apple, the Meltdown fix has no measurable performance reduction across several benchmarks.

The Spectre Safari mitigations have "no measurable impact" on Speedometer and ARES-6 tests, and an impact of less than 2.5% on the JetStream benchmark.

Many PCs with Intel processors have been facing serious issues following the installation of patches with fixes for Meltdown and Spectre, but these problems do not appear to impact Apple's machines.

Related Forum: macOS High Sierra

Top Rated Comments

nexu Avatar
74 months ago
Can we get the same for iOS 10?
Score: 12 Votes (Like | Disagree)
Paddle1 Avatar
74 months ago
How about iOS 9 or iOS 10? Lots of devices stuck there.
Score: 12 Votes (Like | Disagree)
zorinlynx Avatar
74 months ago
I wonder how reliable Apple's patches are given that Linus Torvalds has condemned the patches ('https://lkml.org/lkml/2018/1/21/192') submitted to the linux kernel by Intel:




Linus is never one to mince words...
That's one thing I love about him. He loves Linux and he wants to make it the best system it can be. He doesn't bother with political correctness or being nice. If someone writes bad code, he lets them know, harshly. Everyone who works with him knows not to take things personally.

We need more people like that in QC and management positions at companies like Apple. Steve Jobs was much the same way.
Score: 11 Votes (Like | Disagree)
vicviper789 Avatar
74 months ago
i guess my ibook g4 will be left vulnerable...
Score: 6 Votes (Like | Disagree)
lionel77 Avatar
74 months ago
So, no fixes for Yosemite...
Is it possible to just get El Capitan or Sierra instead of the useless High Sierra...?
Yes, fortunately you can still get those installers:
https://support.apple.com/en-us/HT208202 (Sierra)
https://support.apple.com/en-us/HT206886 (El Capitan)
Score: 6 Votes (Like | Disagree)
Dangermen Avatar
74 months ago
I shouldn't really reply to someone that joined in October 2017 only to post criticism (not a single positive post).
However, I will point out that one could say all security measures are "half-hearted" in that they address an issue (or a group of them) when many others are either in the pipeline or about to be discovered.
If you cannot get to terms with this fact of computing life then perhaps you should give up computers altogether.

I hate to point out the obvious, but when I am not happy with a service provider I usually move to one that I perceive to be a better one. Have you considered this as an option?
Since when does being a forum member for a short period of time exclude my opinion? I've been in IT for 28 years. I started with Linux and I've been a Mac user for 7 years now. I'm heavily invested in them. Switching isn't A) cheap nor B) is my opinion not the source of the problem.

I am asking for Apple to just be more transparent. As an example, pick the last year of the OS release your running that isn't the current OS, then add up all of the discovered vulnerabilities in the following years and those are the holes you are running with. e.g. a 2015 OS has 540+ holes Apple will -never- fix. So patching spectre and meltdown isn't throwing anyone a bone.
https://www.cvedetails.com/product/15556/Apple-Iphone-Os.html?vendor_id=49

Cisco is not a perfect company but their EOL policy is transparent and certainly works better than Apples. They could learn something from them.
https://www.cisco.com/c/en/us/products/eos-eol-policy.html

Asking Apple to do better is not picking on them, I'm a very concerned customer. I had to dump a fully functional Mac mini because Apple stopped producing patches. That latest iMessage crash bug, not fixed in Sierra. I now have a new mac.

---

One last thing, I joined in October because of precisely this issue. I want to raise awareness so that Apple improves their response, not continue with it's current fog of a policy.
Score: 5 Votes (Like | Disagree)

Popular Stories

iOS 17 and iPhones Feature

iOS 17: 10 New Features That Just Launched

Sunday September 17, 2023 12:35 pm PDT by
In June, Apple announced iOS 17 with a wide range of new features and changes for the iPhone. Following over three months of beta testing, the free software update will be released this Monday, September 18 for the iPhone XS and newer. Below, we have recapped 10 key features coming to the iPhone with iOS 17, with additional features coming later this year. The update should be released to...
iPhone 15 Pro Lineup Feature

iPhone 15 Models Feature New Setting to Strictly Prevent Charging Beyond 80%

Tuesday September 19, 2023 2:04 pm PDT by
All of the iPhone 15 and iPhone 15 Pro models feature a new battery health setting that prevents the devices from charging beyond 80% at all times when enabled, as confirmed by The Verge's Allison Johnson during a Q&A session today. The new setting is separate from the pre-existing Optimized Battery Charging feature on iPhones, which intelligently delays charging past 80% until a more...
maxresdefault

Apple Releases iOS 17 With StandBy, Live Voicemail, Improved Autocorrect, FaceTime Video Messages and Tons More

Monday September 18, 2023 10:05 am PDT by
Apple today released iOS 17 and iPadOS 17, the latest operating system updates that are designed for the iPhone and iPad. As with all of Apple's software updates, iOS 17 and iPadOS 17 are available for free. iOS 17 is compatible with the iPhone XR/iPhone XS and later, while iPadOS 17 runs on the iPad mini 5 and later, the iPad 6 and later, iPad Air 3 and later, the second-generation 12.9-inch...
flighty standby

Best Apps With New iOS 17 and watchOS 10 Features

Monday September 18, 2023 3:02 pm PDT by
With the release of a new operating system, there are multiple features and design elements for developers to adopt. Now that iOS 17 is out, many major apps are getting interesting updates today, which we've rounded up below. watchOS 10 also has a new design language, so there are a range of Apple Watch updates to check out too. Flighty (Free, Premium Subscription) Popular flight tracking...