# Threat Model Thursday: Chromium Post-Spectre

DevFeed: [Threat Model Thursday: Chromium Post-Spectre](<https://devfeed.tech/articles/threat-model-thursday-chromium-post-spectre-37072.md>)

Original publisher: [Read original article](<https://shostack.org/blog/tmt-chromium-post-spectre/>)

Author: Adam

Published: 2018-06-14T00:00:00Z

Content type: opinion

Language: en

Sources: [Shostack & Friends Blog](<https://devfeed.tech/sources/shostack-friends-blog.md>)

Topics: [Chromium](<https://devfeed.tech/topics/chromium.md>), [Security](<https://devfeed.tech/topics/security.md>), [Google](<https://devfeed.tech/topics/google.md>), [browser](<https://devfeed.tech/topics/browser.md>), [web-standards](<https://devfeed.tech/topics/web-standards.md>)

Tags: [chrome](<https://devfeed.tech/tags/chrome.md>), [chromium](<https://devfeed.tech/tags/chromium.md>), [css](<https://devfeed.tech/tags/css.md>), [google](<https://devfeed.tech/tags/google.md>), [javascript](<https://devfeed.tech/tags/javascript.md>), [security](<https://devfeed.tech/tags/security.md>), [web](<https://devfeed.tech/tags/web.md>), [web-browser](<https://devfeed.tech/tags/web-browser.md>)

## AI overview

An analysis of Google's "Post-Spectre Threat Model Re-Think," focusing on Chromium and Chrome renderer-process security boundaries. It discusses broader risks in software that runs code from multiple sources within a single address space, including confidentiality breaks, clock jitter, timer precision, and autofilled data handling.

## Source excerpt

Understanding Google's Post-Spectre threat model