Notorious Specter CPU vulnerability hits JIT engines again via side-channel attacks
- New Specter variant exploits processor prediction behavior in just-in-time compilers
- Researchers Demonstrated Practical Attacks Against Intel-Based Linux Systems
- Vendors Release Mitigations as Security Teams Evaluate Performance Tradeoffs
The feared Specter vulnerability that sent chipmakers scrambling for a fix a few years ago has returned, experts said.
Security researchers from the Vrije Universiteit in the Netherlands and the Scuola Superiore Sant’Anna in Italy published a new report detailing a type of attack they call Branch Target Reuse (BTR).
They labeled it the first practical in-place Specter v2 attack targeting just-in-time (JIT) compilers, and there’s a lot to decompile (pun intended), so let’s break it all down.
Latest videos ofTechnologyRadar
Spectrum and fusion
Modern microprocessors come with a feature called “speculative execution”: they speculate what the next moves of a program might be and load them in advance, so that when a scenario actually happens, it can be executed fairly quickly.
They also monitor recurring patterns and try to remember them, but this also opens the door to so-called “side channel attacks,” which allow threat actors to steal information by observing indirect clues from a system (time, power consumption, etc.), rather than accessing them directly.
In 2017, security researchers discovered that speculative execution can be abused through side-channel attacks, giving rise to two vulnerabilities: Specter and Meltdown. Given the extent of the bugs (virtually all chips were affected) and their potential severity, the entire industry rushed to fix the bugs with software patches. Some were successful, but the overall effort was more of a fiasco than a success. Many chips were significantly limited and some computers were completely bricked.
Specter and Meltdown were eventually fixed, but since then, there have been countless imitators and variants. Now we have a new variant, called Branch Target Reuse (BTR).
BTR
When a processor wants to “remember” a recurring topic, it stores it in something called a Branch Target Buffer (BTB). At the same time, there is an element called “JIT”. Short for just-in-time, it is a compiler that translates code into native machine instructions during program execution, rather than before executing it. In practice, JIT creates code at memory address X and then executes it numerous times. The CPU learns the pattern and tries to repeat it.
So when JIT removes the code and puts something else at the same X address, that’s where the problems start, as the CPU still tries to jump to X first. This is called branch target reuse. The CPU will eventually realize that old habits no longer work, but it’s the moment in between that the researchers managed to exploit.
What makes BTR particularly dangerous is the fact that it is not necessary to create new malware to exploit it. Threat actors can simply take advantage of the fact that machine code bytes can mean different things when execution starts at a different byte offset.
In the article, the researchers detail two proof-of-concept (PoC) exploits that can target Intel-based Linux kernels, revealing the root password hash even with the constant binding defense provided by cBPF. The expected leak rate is 5.7 KB/s for Intel Raptor Cove chips and 5.4 KB/s for Lion Cove, which The Register says is “slow but sufficient for an unprivileged user to obtain a sensitive password hash from a vulnerable system.”
Linux and Oracle kernel developers responded with mitigations. The bugs now have two CVEs: CVE-2026-64507 and CVE-2026-64508. Mozilla decided to focus more on site isolation and while IBPB is probably effective, it will slow down the machine. “Update your operating system and software as soon as vendor patches become available,” the researchers said. “Both the Linux kernel and Oracle have released patches.”
The Branch Target Reuse paper, which can be read at this link, was peer-reviewed and accepted by ACM CCS 2026, a major academic conference on cybersecurity, taking place in mid-November this year in The Hague, Netherlands.
Through The Registry
The best antivirus for all budgets
Follow TechRadar on Google News and add us as a preferred source to receive news, reviews and opinions from our experts in your feeds.



Post Comment