But it's still going to help exploits against the browser, isn't it? Letting code poke around until it finds addresses it needs or something like that.
As I understand it (though I don't work directly on Chrome), a key part of Chrome's threat model is that a compromised renderer process (where there is one renderer process per site) has limited security impact. So being safe against Spectre (which gives a read primitive in the renderer process) is just a subset of being safe against a compromised renderer process.
Per site isolation =]
Which the (comparably) insecure likes of Firefox (unfortunately) does not have.
Not yet! But soon. :) See Project Fission [1]. Currently if you're using Beta or Nightly you can toggle it on and I believe it is getting very close to being ready to ship.