Important Update: Effective July 1, 2026, Zebra is implementing mandatory Multi-Factor Authentication (MFA) to enhance security. Learn more.

Spectre and Meltdown Update Schedule and FAQs

This bulletin will continue to be updated as new information becomes available. We recommend you subscribe to email updates to be notified when new files are posted. 

Downloads

Locate your product below to view release schedule and access updates. If your product is not listed, Contact Technical Support.

What is the CVE Information for Spectre and Meltdown?

This class of vulnerabilities that encompass 3 CVEs which form Spectre and Meltdown. These vulnerabilities can be exploited as "speculative execution side-channel attacks" executed by malware. The malware can impact many modern processors and operating systems including Intel, AMD, and ARM.

  • Variant 1 – CVE-2017-5753, Spectre: Bounds check bypass
  • Variant 2 – CVE-2017-5715, Spectre: Branch target injection
  • Variant 3 – CVE-2017-5754, Meltdown: Rogue data cache load, memory access permission check performed after kernel memory read
  • CVE-2017-13218 is a general case mitigation for side-channel attacks that also addresses this issue. 

Why am I being asked to login to Zebra.com to download the update?

For mobile computers and scanners, updates are available to registered Zebra.com users with a valid warranty or service contract. 

For printers, firmware updates are available to registered Zebra.com users.

I am logged into zebra.com. Why am I not able to download the update?

For mobile computers and scanners, the device must have a valid warranty or service contract. If you do not have a valid warranty or service contract, the update cannot be downloaded. Refer to question above for additional options.

If you have a valid warranty or service contract and the download fails, contact Zebra’s Technical Support Help Desk.

For printer firmware download failures, contact Zebra’s Technical Support Help Desk.

Disclaimer: Zebra makes every attempt to release security updates on or about the time that Google releases its respective security bulletin. However, delivery time of security updates may vary depending on the region, product model, and third party software suppliers. Under some circumstances, the OS must be updated to the latest maintenance release prior to installing the security updates. Individual product updates will provide specific guidance.

Unless otherwise noted, there have been no reports of active customer exploitation or abuse from these newly reported issues.



Are you aware of a potential security issue with a Zebra Technologies product?