Researchers from the VUSec group at Vrije Universiteit Amsterdam and Scuola Superiore Sant’Anna in Italy have disclosed a new variant of the Spectre v2 attack, which they named Branch Target Reuse (BTR). This variant affects systems powered by Intel, AMD, and Arm CPUs.
The BTR attack targets just-in-time (JIT) compilers used by operating system kernels, web browsers, and runtimes. It exploits how processors handle code that changes at runtime, specifically focusing on stale indirect branch prediction entries.
The core of the BTR attack lies in the observation that while modern CPUs restore architectural code coherence after self-modification, they do not necessarily invalidate stale indirect branch prediction entries. In JIT engines, these stale predictions can outlive the code they were created for and be reused when new code is written to the same memory.
This process creates a 'transient execute-after-free primitive,' allowing attackers to hijack transient control flow to newly generated code at obsolete offsets. This can bypass software hardening or reach misaligned gadgets, enabling the extraction of sensitive data.
An attacker able to run code on a targeted machine could exploit BTR to steal sensitive data from memory, such as password hashes. The researchers demonstrated that BTR can recover root password hashes from Intel computers running Linux in just a few minutes.
Attacks launched from malicious web pages also appear feasible, though a complete browser exploit has not yet been built. The researchers evaluated BTR against Firefox's JavaScript engine SpiderMonkey, GraalVM, and the Linux kernel's cBPF JIT, finding all to be affected to varying degrees.
This discovery is significant because it demonstrates that self-modifying code (SMC)-based transient execution attacks are practical in real-world environments, a finding that challenges previous assumptions in the field since 2018. The attack shows that even fully patched Intel systems can be vulnerable.
Fixes for the identified vulnerabilities, tracked as CVE-2026-64507 and CVE-2026-64508, have been merged into the Linux kernel to address the BTR threat.
✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →
One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.
One email a day. Unsubscribe in one click, any time.
Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.
▶ Play today's briefNew every morning, and the back catalogue is archived by date.
Academics have disclosed a new Spectre-v2 variant, named Branch Target Reuse (BTR), that affects JIT engines in web browsers, language runtimes, and the Linux kernel across multiple CPU vendors. This vulnerability allows attackers to leak sensitive data, such as root password hashes from fully patched Intel systems, by exploiting stale indirect branch prediction entries.
Researchers discovered a new Spectre v2 attack variant, Branch Target Reuse (BTR), that can extract root password hashes from Intel Linux systems. The attack exploits stale branch predictor information after JIT engines reuse memory, demonstrating the practicality of self-modifying code-based transient execution attacks in real-world environments. Fixes for the identified vulnerabilities (CVE-2026-64507 and CVE-2026-64508) have been merged into the Linux kernel.
Researchers have discovered a new Spectre v2 variant, named Branch Target Reuse (BTR), that impacts Intel, AMD, and Arm CPUs. This vulnerability allows attackers to steal sensitive data from memory by exploiting how processors handle code that changes at runtime, specifically targeting just-in-time (JIT) compilers.