Thanks for summarizing. Does anyone have time to link to more on the "side-channel leaking kernel address information into userland via JavaScript" ?
EDIT: This post[2] discusses the specific speculative execution cache attack and claims there is a JavaScript PoC (but doesn't cite a source for that claim)
[1] https://www.youtube.com/watch?v=ewe3-mUku94
[2] https://plus.google.com/+KristianK%C3%B6hntopp/posts/Ep26AoA...
Also, RUH-ROH. https://twitter.com/brainsmoke/status/948561799875502080