Intel begins issuing patches to combat Spectre and Meltdown flaws, with plans to release updates for 90% of chips from past five years this week
Jeremy Horwitz / VentureBeat :
Context & Ripple Effects
The Spectre and Meltdown disclosures put Intel in emergency remediation mode, and this week's push to update 90% of chips from the past five years is the first mass deployment of microcode fixes for a flaw class that lives inside the CPU itself rather than the software running on it. The scope is what makes it unprecedented: nearly every processor Intel has shipped since 2012 needs a fix.
The rollout immediately ran into trouble — Intel later admitted the patches also hit newer Skylake and Kaby Lake chips with performance impacts between 2% and 25% and had to reissue them after early versions crashed some systems. The episode ended with a structural answer: Intel's CEO committed to shipping future chips with built-in Meltdown and Spectre protections rather than relying on post-hoc patches.
First-order effects
- Owners of Intel chips from the past five years get microcode and firmware updates this week, changing how their systems handle memory access at the cost of measurable performance overhead.
Second-order effects
- Patch quality becomes a competitive liability: when early fixes crashed systems and slowed Skylake-era machines by up to 25%, every re-release had to be validated per platform — a cadence Intel spent February stabilizing across Skylake variants before broader rollouts.
Third-order effects
- Speculative execution turned out to be a recurring attack surface rather than a one-off bug — researchers later detailed Foreshadow, a related flaw in Intel's secure enclaves — pushing the industry toward fixing these issues in silicon, as Intel's built-in-protection chip plans signal, instead of patching around them in microcode.
The trend: CPU security is shifting from software-side patching to hardware redesign, as speculative execution flaws force chipmakers to build mitigations into future silicon.