Skip to main content

Google Chrome now consumes more memory due to a new Spectre fix

Microsoft Surface Pro 4 Chrome

Version 67 of Google’s Chrome browser for Windows, Mac, Linux, and Chrome OS now includes a new security feature called Site Isolation. This new component protects web surfers against Spectre-based attacks on the internet but for a price: 10 to 13 percent more system memory consumption.

Spectre — along with Meltdown — is a design flaw in modern processors that enable hackers to gain access to data stored in memory. This data is supposedly off limits, but the method processors use to predict the outcome of their current task leaves that data exposed. Hardware and software manufacturers have scrambled to fix these flaws since their initial reveal in January.

While the typical scenario sees a hacker physically accessing a computer and running custom code to read sensitive data stored in memory, an attack can happen across the internet as well. According to Google, browsers run potentially malicious JavaScript code in the background from multiple websites and in many cases within the same process. That means a website could steal data stored in memory stemming from other websites.

Although all major web browsers include “some mitigations” to prevent Spectre-based attacks, Google believes Site Isolation is the best approach. Prior to version 67, Chrome relied on a multi-process architecture that allowed each tab to have its own web page rendering process. The problem is that many websites use frames (aka iframes) to compile different web-based components together into a single page: Components that are used across multiple sites. The page may even display cross-site pop-ups too.

That said, all of this rendering resides within a single process. But if one of those components or pop-ups include malicious JavaScript that exploits the Spectre flaw, they could read data residing in the system memory that is stored by the other components of the page. Data may include passwords, cookies, credit card numbers, and so on.

With Site Isolation, pages aren’t rendered in a single process. Instead, the website’s mainframe has its own render process while all other cross-site components have their own individual “out of process” rendering. This is why the browser’s memory consumption increased up to 13 percent.

According to Google, splitting a single page across multiple processes is a major change to how Chrome displays a single page.

“The Chrome Security team has been pursuing this for several years, independently of Spectre,” states Google’s Charlie Reis. “Site Isolation is a significant change to Chrome’s behavior under the hood, but it generally shouldn’t cause visible changes for most users or web developers.”

Although Site Isolation is baked into Chrome 67 for Windows, Mac, Linux and Chrome OS, only 99 percent of those installs will actually have the feature running in the background. The remaining one percent will stay inactive as Google monitors and improves performance.

Does that mean the team will trim off Chrome’s 10 to 13 percent added memory consumption? Time will tell, and given that Chrome already gobbles memory like a kid on Halloween, the extra Spectre-based consumption could be an unwanted setback for machines with low amounts of system memory.

Kevin Parrish
Former Digital Trends Contributor
Kevin started taking PCs apart in the 90s when Quake was on the way and his PC lacked the required components. Since then…
Google Chrome now tracks prices, remembers abandoned shopping carts
google chrome update shopping inline no shell v2

Google is looking to make your online shopping easier, by saving you time and money. The Internet search giant has rolled out a few new features, which when combined with Chrome's autofill and automatic password generator to create safe logins for new websites, will reduce the friction and headache from finding the right prices online.
The first feature is the ability to quickly track price history on mobile. The feature will arrive first on Chrome for Android and follow in the coming weeks to Chrome for iOS. Essentially, mobile users will be able to open up the browser's tab grids, Google said of the feature. Along with tabs of recently opened web pages, you'll see the latest price drops highlighted at the top of each tabbed page, making it easy to identify which items are currently on sale.

Google's latest online shopping efforts follow that of rival Microsoft, which had recently launched a shopping extension for its own Microsoft Edge browser with similar price tracking features designed to save you money.

Read more
Google Chrome has a secret feature to make it match Windows 11’s new design
Google Chrome opened on a laptop.

One of the signature features of Windows 11 is the new rounded corners and glass-like mica effects. Usually only found in Microsoft and select third-party Windows apps, these design elements are now making their way into Google Chrome but are still hidden secret behind a flag in Chrome's settings.

Once the secret flag is enabled, Chrome on Windows 11 fits in better with the rest of the new operating system. Right-click menus in Chrome change from squared off to more rounded, and also pick up the modern mica effect. In addition, Chrome's pop-out settings menu changes to a more rounded shape, fitting better with native Windows elements like the Start Menu and Quick Actions pop-out.

Read more
Update Google Chrome now to patch this critical security flaw
A MacBook with Google Chrome loaded.

You might want to update your Google Chrome web browser right away. Google recently issued a critical security update for Chrome, patching up 11 security issues, including two zero-day vulnerabilities that were exploited in the wild.

Released on September 13, Google first listed the patched vulnerabilities on the Chrome Releases blog. Full details are being withheld for security reasons, as Google wants a majority of users to update first.

Read more