There are only few things running untrusted code on a typical end-user system, most notably the browsers executing javascript. Now that would be attack-able. But then again, it seems unlikely that anybody would launch broadly deployed attacks, as the vast majority of systems would run with mitigations on, so it's just not worth the trouble considering that and considering that you also have to get lucky to actually extract something valuable (and recognize it is valuable). On top of that, browsers also bring a bunch of mitigations that make it harder to exploit these bugs even if system mitigations are disabled.
I'm personally not very concerned about anybody trying to attack me with spectre/meltdown class bugs that can be and are usually mitigated, even with mitigations disabled on my system. If somebody wanted to attack me, either at random (broad attack), or targeting me specifically, they'd have far better ways and targets to try first than hoping I'd visit their website and run without mitigations enabled and have something valuable in my memory.
This is different if it's a shared system, like cloud machines/shared hosting, where this is an class of bugs is far more of a concern. And if you know or have reason to suspect you're a specific target, then you might err on the side of caution as well.
These attacks are being done algorithmically, automatically now.
Seriously, I haven't seen any news of these attacks being used against end-user systems, either broadly or targeted. Have some links?
edit: Think of cars on a racetrack. Street worthiness considered ballast...ROAAARRRR!
https://garudalinux.org/images/garuda/ss/garuda-boot-options...
I'm not sure whether this is misleading or not given the nature of illustrative screenshots, e.g. the package management one shows VLC installed but not Firefox:
https://nvd.nist.gov/vuln/detail/CVE-2017-5754
https://nvd.nist.gov/vuln/detail/CVE-2018-3639
> A ddg site search of "cve" returns zero hits.
What was your search query?