- Academics disclosed a new Spectre-v2 CPU vulnerability variant, Branch Target Reuse (BTR), affecting JIT engines across multiple CPU vendors.
- The attack exploits the interplay between Self-Modifying Code and indirect branch prediction to hijack control flow and disclose secret data.
- End-to-end exploits were demonstrated against the Linux kernel, leaking root password hashes from a fully patched Intel system in minutes.
- Mitigations have been released for the Linux kernel as CVE-2026-64507 and CVE-2026-64508, with GraalVM and Mozilla Firefox implementing their own defenses.
A group of academics from VUSec and Scuola Superiore Sant’Anna disclosed details of a new Spectre CPU vulnerability variant that affects Just-In-Time (JIT) engines across multiple CPU vendors. The new Spectre-v2 variant, codenamed Branch Target Reuse (BTR), was detailed in a paper by researchers Sander Wiebing, Yuhui Zhu, Alessandro Biondi, and Cristiano Giuffrida.
“The key insight is that, while modern CPUs restore architectural code coherence after self-modification, they do not necessarily invalidate stale indirect branch prediction entries,” the researchers explained. Consequently, attackers can hijack transient control flow to newly generated code at obsolete offsets, bypassing software hardening.
BTR was evaluated against SpiderMonkey (the JIT engine of Mozilla Firefox), GraalVM, and the Linux kernel‘s cBPF JIT, all of which were found to be affected. As a proof-of-concept, two end-to-end exploits were devised against the Linux kernel to leak and recover the root password hash within minutes from a fully patched Intel system.
Spectre refers to a class of CPU security vulnerabilities first discovered in 2017 that exploit speculative execution. An attacker can exploit this loophole to trick a CPU into performing speculative operations that access sensitive data, then infer that data through a cache timing side channel.
“BTR targets JIT engines and arises from the interplay between Self-Modifying Code (SMC) and indirect branch prediction,” the researchers said, adding that JIT engines expose exploitable transient-execution opportunities induced by SMC for the first time. The attack presumes an attacker who can run unprivileged code in a JIT engine and seeks to disclose sensitive data from the host environment.
Following responsible disclosure, mitigations for BTR have been released and merged into the Linux kernel as CVE-2026-64507 and CVE-2026-64508. Meanwhile, GraalVM hinders region reuse by randomizing JIT code-cache locations, and Mozilla considered IBPB-based mitigations while prioritizing the completion of site isolation.
✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.
