Urbit is maybe a sort of "extreme langsec." "Immune" is a dangerous word. Urbit is "premitigated" against Spectre for the following reasons, some cool and others stupid:
(1) The Nock VM has no O(n) data structures, ie, arrays. This was not anything to brag about till now.
(2) Urbit events are interpreted in their own process, which is one trust domain (one process, one "personal server").
(3) A personal server isn't a browser and doesn't habitually run code its owner doesn't trust.
(4) Urbit is purely functional, so you only know the time if someone passes you the time.
(5) Top-level event handlers are passed the time of the event. This is easy to fuzz.
(6) If you are running untrusted foreign code, it is probably just a function. Giving this function a measured time interval from top-level event times would be strange. And it would need another channel to exfiltrate the stolen data.
Never say never, but this combination of premitigations makes me worry about Spectre very little. Although, when we do have a less-trusted tier of applications (walk before run), ain't nobody is going to be telling them the time.
Besides the plug, the lesson there is that one of the reasons Spectre is a problem is that langsec is an imperfect bandaid.
Urbit is premitigated because it was designed as a functional system from the ground up. The JS environment is functional lite -- it allows typeless functional programming, but it also retains many mutable/imperative systems design tropes.
It's these tropes that have become clever attack vectors. If you don't want to get Spectred, build systems that are formal and functional all the way down.