I only had a chance for a brief read over the papers, and to be frank, a lot of it goes over my head.
However, from what I'm understanding, this makes Heartbleed look like a papercut.
However, from what I'm understanding, this makes Heartbleed look like a papercut.
Edit: Wait, sorry, I misread. Read is all you really need, write would just be a cherry. If you can read the memory of the host kernel, then you can gain access to any other VMs on the system. This one is bottom-up, you need access to one system and in theory you can gain access to thousands.
… and nowadays almost everyone permits remote sites to execute code in their browsers. I don't know if JavaScript can be used to implement Meltdown though.
This research has implications for products and services that execute externally supplied code, including Chrome and other browsers with support for JavaScript and WebAssembly.