Remember defense is depth is a valid strategy.
The headline is "patch available, mitigating known exploit". "Not yet widely exploited" is barely a footnote. The release of a patch can bring enough attention to make the window between release and full deployment of the patch the single worst time to be vulnerable. If I tell you it wasn't being exploited yesterday, and you delay patching based on that information, and then the storm of exploits blows through ... I'd feel bad.
Maybe you wouldn't, but US-CERT, Mozilla, etc. do...
https://www.us-cert.gov/ncas/current-activity/2019/06/18/Moz...
https://www.mozilla.org/en-US/security/advisories/mfsa2019-1...
Really? This isn't how security works? Yeah, I guess I forgot security is a 100% binary thing. That's why you never read actual security bulletins advising you when vulnerabilities are actively being exploited in the wild. It's insane to think that should matter or raise the urgency of a patch. [1] [2]
[1] https://www.us-cert.gov/ncas/current-activity/2019/06/18/Moz...
[2] https://www.mozilla.org/en-US/security/advisories/mfsa2019-1...
Spectre probably isn't possible either and that is the easy one. The load store buffer attack seems completely impossible. Even the POC had to essentially write a program specially to be exploited.
The attacks are very interesting and neat, but I think things like this and other techniques effectively remove any last chance.