A new Spectre v2 variant called Branch Target Reuse (BTR) has been disclosed by academics from VUSec and Scuola Superiore Sant'Anna. The attack targets Just-In-Time (JIT) engines in web browsers, language runtimes, and operating system kernels, abusing the interaction between self-modifying code and indirect branch prediction. According to the researchers, modern CPUs restore architectural code coherence after self-modification but do not always invalidate stale indirect branch prediction entries, creating a transient execute-after-free primitive that can bypass existing Spectre hardening.
The researchers evaluated BTR against Mozilla Firefox's SpiderMonkey, GraalVM, and the Linux kernel's cBPF JIT, finding all affected but with different exploitability and leakage rates. As a proof of concept, they built two end-to-end exploits against the Linux kernel that can leak and recover the root password hash within minutes from a fully patched Intel system with default protections. The sources agree on this core result, though they differ on the affected CPU scope: BleepingComputer emphasizes Intel systems, while The Hacker News says the flaw spans multiple CPU vendors and SecurityWeek explicitly names Intel, AMD, and Arm.
Mitigations are already in motion. The Linux kernel has received patches tracked as CVE-2026-64507 and CVE-2026-64508, and GraalVM hinders region reuse by randomizing JIT code-cache locations. Mozilla has considered IBPB-based mitigations but is currently prioritizing the completion and deployment of site isolation. The attack assumes an attacker who can run unprivileged code inside a JIT engine, making browser isolation and kernel JIT hardening key fronts in limiting exposure.