Apple Faces Meltdown & Spectre Class Action Lawsuit

Apple is facing a class action lawsuit in the US over the industry-wide chip vulnerabilities known as ‘Meltdown’ and ‘Spectre’.

Essentially, the vulnerabilities affect the kernel of the chips and could allow an attacker to read information that should otherwise be inaccessible. This means an attacker could obtain passwords, encryption keys or steal information from other applications.

Chips made by Intel, AMD and ARM manufacturers are all affected, meaning all manner of devices are implicated.

Meltdown & Spectre Apple

This includes iPhones, iPads and Apple TV devices powered by Apple’s processor technology, which is built on ARM’s designs.

Apple confirmed iOS, tvOS and macOS were all vulnerable and has released mitigations. It is worth noting that the Mac and the Intel chips used to power the computers are not directly addressed in this lawsuit, although Intel itself is facing legal action.

Lawyers allege that Apple has known about the bugs in June and that fixes released for Meltdown so far have impacted performance. Furthermore it is claimed that Spectre has still not been sufficiently patched and there is no indication what effect that could have on the devices in question.

Had customers known this information, it is argued, they would not have bought the products in question and certainly not for the prices they had paid for them.

Loading ...

“In short, Defendant has not been able to offer an effective repair to its customers. A patch that cuts processor performance is not a legitimate solution, nor is any patch that does not fully eliminate the Security Vulnerabilities that can be exploited by the Meltdown or Spectre techniques,” reads the filing made to the US District Court for the Northern District of California in San Jose.

Silicon has contacted Apple for comment, but earlier this month it said it had no information on the vulnerabilities being exploited in the wild.

Microsoft has already issued an emergency patch for Windows 10, while Google has urged Android users to upgrade to the latest security update.

Public cloud providers, including Amazon Web Services (AWS), Google Cloud Platform (GCP) and Microsoft Azure have also issued guidance to customers in what is arguably an unprecedented incident for the technology industry.

Quiz: What do you know about ARM Holdings?

Steve McCaskill

Steve McCaskill is editor of TechWeekEurope and ChannelBiz. He joined as a reporter in 2011 and covers all areas of IT, with a particular interest in telecommunications, mobile and networking, along with sports technology.

Recent Posts

Tesla Axes Entire Supercharger Team, Plus Senior Executives

Elon Musk dismisses two senior Tesla executives, plus the entire division that runs Tesla's Supercharger…

15 mins ago

Microsoft, OpenAI Sued By More Newspaper Publishers

Eight newspaper publishers in the US allege Microsoft and OpenAI used their millions of their…

1 hour ago

Binance’s Changpeng Zhao Sentenced To Four Months In Prison

US judge sentences Binance founder, Changpeng Zhao, to four months in prison for ignoring money…

4 hours ago

OpenAI Hit By Austrian Complaint Over ChatGPT ‘False Data’

Rights group argues ChatGPT tendency to generate false information on individuals violates GDPR data protection…

1 day ago

EU Designates Apple’s iPad OS As DMA ‘Gatekeeper’

European Commission says Apple's iPadOS is 'gatekeeper' due to large number of businesses 'locked in'…

1 day ago

Beating the Barbarians in the Cloud

As the cloud continues to be an essential asset for all businesses, developing and maintaining…

1 day ago