← All stories
● Covered by 3 sources · 3 reportsMedium impact3 negative

New Spectre v2 Variant (BTR) Affects Intel, AMD, Arm CPUs, Leaks Sensitive Data

🔄 Updated 2d ago
New to BrevFeed? We gather this story from every outlet covering it into one summary — ranked by real-world impact, not just the latest headline — so you never miss what matters. What is BrevFeed? →

Key points

  • New Spectre v2 variant, Branch Target Reuse (BTR), discovered by VUSec and Scuola Superiore Sant'Anna.
  • Affects Intel, AMD, and Arm CPUs by exploiting JIT compilers.
  • Can leak sensitive data like root password hashes from Linux systems.
  • Fixes for CVE-2026-64507 and CVE-2026-64508 merged into Linux kernel.
  • Demonstrates practicality of self-modifying code-based transient execution attacks.

New Spectre v2 Variant Identified

Researchers from the VUSec group at Vrije Universiteit Amsterdam and Scuola Superiore Sant’Anna in Italy have disclosed a new variant of the Spectre v2 attack, which they named Branch Target Reuse (BTR). This variant affects systems powered by Intel, AMD, and Arm CPUs.

The BTR attack targets just-in-time (JIT) compilers used by operating system kernels, web browsers, and runtimes. It exploits how processors handle code that changes at runtime, specifically focusing on stale indirect branch prediction entries.

Mechanism of the Attack

The core of the BTR attack lies in the observation that while modern CPUs restore architectural code coherence after self-modification, they do not necessarily invalidate stale indirect branch prediction entries. In JIT engines, these stale predictions can outlive the code they were created for and be reused when new code is written to the same memory.

This process creates a 'transient execute-after-free primitive,' allowing attackers to hijack transient control flow to newly generated code at obsolete offsets. This can bypass software hardening or reach misaligned gadgets, enabling the extraction of sensitive data.

Real-World Impact and Demonstrations

An attacker able to run code on a targeted machine could exploit BTR to steal sensitive data from memory, such as password hashes. The researchers demonstrated that BTR can recover root password hashes from Intel computers running Linux in just a few minutes.

Attacks launched from malicious web pages also appear feasible, though a complete browser exploit has not yet been built. The researchers evaluated BTR against Firefox's JavaScript engine SpiderMonkey, GraalVM, and the Linux kernel's cBPF JIT, finding all to be affected to varying degrees.

Significance and Mitigations

This discovery is significant because it demonstrates that self-modifying code (SMC)-based transient execution attacks are practical in real-world environments, a finding that challenges previous assumptions in the field since 2018. The attack shows that even fully patched Intel systems can be vulnerable.

Fixes for the identified vulnerabilities, tracked as CVE-2026-64507 and CVE-2026-64508, have been merged into the Linux kernel to address the BTR threat.

✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →

The daily brief

One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.

One email a day. Unsubscribe in one click, any time.

Today's brief

Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.

~34 min · 27 stories · Oct 02

▶ Play today's brief Listen on Spotify

New every morning, and the back catalogue is archived by date.

How outlets covered it

Academics have disclosed a new Spectre-v2 variant, named Branch Target Reuse (BTR), that affects JIT engines in web browsers, language runtimes, and the Linux kernel across multiple CPU vendors. This vulnerability allows attackers to leak sensitive data, such as root password hashes from fully patched Intel systems, by exploiting stale indirect branch prediction entries.

Researchers discovered a new Spectre v2 attack variant, Branch Target Reuse (BTR), that can extract root password hashes from Intel Linux systems. The attack exploits stale branch predictor information after JIT engines reuse memory, demonstrating the practicality of self-modifying code-based transient execution attacks in real-world environments. Fixes for the identified vulnerabilities (CVE-2026-64507 and CVE-2026-64508) have been merged into the Linux kernel.

Researchers have discovered a new Spectre v2 variant, named Branch Target Reuse (BTR), that impacts Intel, AMD, and Arm CPUs. This vulnerability allows attackers to steal sensitive data from memory by exploiting how processors handle code that changes at runtime, specifically targeting just-in-time (JIT) compilers.