New Spectre Variant 'Branch Target Reuse' Leaks Linux Memory Despite Defenses
Academics have detailed a new Spectre variant, dubbed Branch Target Reuse (BTR), affecting JIT engines in browsers, runtimes, and Linux kernels across multiple CPU vendors, bypassing existing defenses.

A new variant of the Spectre CPU vulnerability, named Branch Target Reuse (BTR), has been disclosed by researchers from VUSec and Scuola Superiore Sant'Anna. This sophisticated attack targets Just-In-Time (JIT) engines found in web browsers, language runtimes, and operating system kernels, affecting processors from multiple vendors. BTR exploits speculative execution, a core performance feature of modern CPUs, to leak sensitive memory contents, demonstrating that even existing Spectre defenses are not entirely foolproof against novel exploitation techniques.
The core of the BTR attack lies in the CPU's handling of indirect branch predictions. While CPUs are designed to maintain code coherence after self-modification, they may not always invalidate stale branch target entries. In JIT engines, which dynamically generate and modify code, these outdated branch targets can persist and be reused when code is repopulated. This allows attackers to hijack transient control flow to code at obsolete offsets, creating a primitive that bypasses software hardening measures and enables access to sensitive data.
Researchers successfully demonstrated BTR against widely used JIT engines, including SpiderMonkey (used in Mozilla Firefox), GraalVM, and the Linux kernel's cBPF JIT. While all were found to be affected, the exploitability and data leakage rates varied significantly across these implementations. As a proof-of-concept, the team developed two end-to-end exploits targeting the Linux kernel, capable of extracting the root password hash from a fully patched Intel system with default protections enabled in mere minutes.
Spectre, first discovered in 2017, represents a class of vulnerabilities that leverage speculative execution. Processors speculatively execute instructions to improve performance, but this can lead to sensitive data being accessed. Attackers can then infer this data through side-channel attacks, such as cache timing. Spectre v2 specifically targets indirect branch prediction, manipulating the CPU's prediction mechanism to speculatively execute attacker-controlled code or gadgets, thereby leaking information based on cache state changes.
The BTR attack specifically targets JIT engines by exploiting the interplay between Self-Modifying Code (SMC) and indirect branch prediction. This is the first time that JIT engines have been shown to expose exploitable transient-execution opportunities induced by SMC. The attack chain involves luring the JIT engine to allocate a training chunk, forcing a branch to it to create a branch target buffer (BTB) entry, deallocating the training chunk, and then reallocating a target chunk that reuses the same address. When the indirect branch is triggered again, the CPU may use the stale BTB entry, speculatively jumping to the old entry point.
This redirection to an architecturally invalid entry point allows attackers to bypass Spectre hardening mitigations or execute misaligned instructions, ultimately leading to the disclosure of secret data. A critical condition for BTR's success is that the stale BTB entry must not be invalidated or replaced after the training chunk is freed, and the branch predictor must select this stale entry for prediction.
Following responsible disclosure, mitigations for BTR have been developed and integrated into the Linux kernel, with specific patches addressing CVE-2026-64507 and CVE-2026-64508. GraalVM has implemented defenses by randomizing JIT code-cache locations to hinder region reuse. Mozilla is considering Indirect Branch Predictor Barrier (IBPB) based mitigations but is currently prioritizing the deployment of site isolation. This disclosure follows closely on the heels of another Spectre v2 bypass technique, Interrupt Injection, revealed by MIT CSAIL researchers.
The ongoing discovery of new Spectre variants underscores the persistent challenges in mitigating hardware-level vulnerabilities. Despite significant efforts to patch and harden systems against known speculative execution attacks, the fundamental design of modern processors continues to present opportunities for novel exploitation. This highlights the need for continuous research and development in hardware security and the importance of staying vigilant against evolving threats.
This new reporting from SecurityWeek details the specific technical mechanism of the Branch Target Reuse (BTR) variant, explaining how it exploits stale indirect branch prediction entries in Just-In-Time (JIT) compilers. It also highlights the potential for exploitation in browsers like Firefox and runtimes such as Oracle's GraalVM, in addition to the previously reported Linux kernel impact.