the Chromium logo

The Chromium Projects

Lazy FP Restore Vulnerability Status for Chrome OS

Vulnerability description

System software utilizing lazy floating point state restore in systems using Intel Core-based microprocessors may potentially allow a local process to infer data from another process through a speculative execution side channel. Exploitation of the vulnerability requires the ability to run native code on the device. CVE-2018-3665

Chrome OS response

Chrome OS 68, which will be released to the stable channel in late July 2018, will provide patches to the OS kernel to mitigate this vulnerability. Chrome OS devices will receive these updates automatically.

Affected devices

Chrome OS Intel devices with Core-based processors may be affected. The cpu line in the chrome:system page will show what CPU the device has.

The following list covers affected devices that will be mitigated in Chrome OS 68:

Marketing name Public codename Platform
Dell Chromebook 13 3380 asuka Skylake-U
Acer Chromebase 24 buddy Broadwell
Samsung Chromebook Pro caroline Skylake-Y
ASUS Chromebook Flip C302 cave Skylake-Y
HP Chromebook 13 G1 chell Skylake-Y
Google Pixelbook eve Kabylake-Y
HP Chromebook 14 falco Haswell
Toshiba Chromebook 2 (2015 Edition) gandof Broadwell
ASUS Chromebox CN62 guado Broadwell
Chromebook 14 for work (CP5-471) lars Skylake-U
Toshiba Chromebook leon Haswell
Acer Chromebook 11 (C771, C771T) lili Skylake-U
Google Chromebook Pixel link Ivy Bridge
Dell Chromebook 13 7310 lulu Broadwell
Acer Chromebox mccloud Haswell
LG Chromebase 22CV241 monroe Haswell
LG Chromebase 22CB25S monroe Haswell
Acer Chromebook 11 (C740) paine Broadwell
ASUS Chromebox CN60 panther Haswell
Acer C720 Chromebook peppy Haswell
Acer Chromebox CXI2 rikku Broadwell
Google Chromebook Pixel (2015) samus Broadwell
Thinkpad 13 Chromebook sentry Skylake-U
Lenovo Thinkpad X131e Chromebook stout Ivy Bridge
Lenovo ThinkCentre Chromebox tidus Broadwell
Dell Chromebox tricky Haswell
Dell Chromebook 11 wolf Haswell
Acer Chromebook 15 (CB5-571) yuna Broadwell
HP Chromebox CB1-(000-099) HP Chromebox G1 HP Chromebox for Meetings zako Haswell