From the spectre paper, https://spectreattack.com/spectre.pdf
"As a proof-of-concept, JavaScript code was written that, when run in the Google Chrome browser, allows JavaScript to read private memory from the process in which it runs (cf. Listing 2). "
That looks like is the current limit of javascript base attack. It doesn't seem to be able to access system resources nor execute system command script (yet....).
That kind of JS attack vector likely can be mitigated with web browser update.