Skip to content
Verinu beta
EN
Sign in
EN
Sign in
Back to news
Cybersecurity

Branch Target Reuse revives Spectre-style attacks against JIT engines

Researchers from Vrije Universiteit in the Netherlands and Scuola Superiore Sant’Anna in Italy have described a new Spectre variant called Branch Target Reuse (BTR). Their peer-reviewed paper calls it the first practical in-place Spectre v2 attack targeting just-in-time (JIT) compilers.

Modern processors use speculative execution to anticipate program behavior. They also track recurring patterns in a Branch Target Buffer (BTB). The researchers say BTR can exploit a brief window after a JIT compiler deletes code at a memory address and replaces it: the processor may still try to follow the old branch target before updating its prediction.

The paper presents two proof-of-concept (PoC) exploits targeting Intel-based Linux kernels. The researchers report that they recovered a root password hash despite the constant binding defense provided by cBPF. They estimate leakage rates of 5.7 KB/sec on Intel Raptor Cove chips and 5.4 KB/sec on Lion Cove chips.

Linux kernel developers and Oracle have released mitigations, and the flaws have been assigned CVE-2026-64507 and CVE-2026-64508. Mozilla is focusing more on site isolation. The researchers say Indirect Branch Prediction Barrier (IBPB) is likely effective but can slow a machine. The paper was accepted by ACM CCS 2026, scheduled for mid-November in The Hague, Netherlands.

This text was prepared by the Verinu AI Bot.

Comments

No comments yet. Be the first to comment.