A collaborative team of academic researchers hailing from VUSec and the Scuola Superiore Sant’Anna has publicly disclosed details regarding a novel Spectre CPU vulnerability variant. This newly uncovered security flaw directly targets Just-In-Time (JIT) compilation engines embedded within modern web browsers, diverse language runtimes, and operating system kernels across multiple CPU vendors. Identified officially as a new variant of the long-standing Spectre v2 class of vulnerabilities, the discovery has been codenamed Branch Target Reuse, or BTR. The findings shed light on a profound oversight in how modern processors handle microarchitectural states during code modification, opening up a sophisticated attack vector that undermines existing software hardening techniques. Read Also: Critical Security Flaw Discovered in Elementor Plugin Threatens Over Two Million WordPress Sites Arista Issues Critical Security Advisory for VeloCloud Orchestrator Flaw Under Active Attack In an accompanying research paper, the academic team—comprising Sander Wiebing, Yuhui Zhu, Alessandro Biondi, and Cristiano Giuffrida—elaborated on the core mechanism behind the vulnerability. The key insight driving the attack is that while modern high-performance CPUs properly restore architectural code coherence following self-modification, they fail to systematically invalidate stale indirect branch prediction entries, commonly referred to as branch targets. Within modern Just-In-Time engines, these stale targets can effortlessly outlive the original code block. Later, when the dynamic code cache is repopulated, the outdated targets can be inadvertently reused. This phenomenon yields what the researchers describe as a transient execute-after-free primitive. Consequently, malicious actors can hijack transient control flow to newly generated code residing at obsolete offsets, effectively bypassing established software hardening mechanisms or reaching misaligned gadgets that would otherwise be inaccessible. To gauge the real-world impact of the discovery, the research team evaluated BTR against several prominent JIT environments. These included SpiderMonkey, which serves as the core JIT engine for Mozilla Firefox, GraalVM, and the cBPF JIT integrated directly into the Linux kernel. All of the tested targets were found to be susceptible, though they exhibited markedly different exploitability characteristics and memory leakage rates depending on their internal architectures. Demonstrating the severity of the threat, the researchers successfully devised two end-to-end exploits targeting the Linux kernel. These proofs-of-concept proved capable of leaking and successfully recovering the root password hash within minutes, even when executed against a fully patched Intel system operating with default security protections enabled. To contextualize the discovery, Spectre refers to a sprawling class of hardware security vulnerabilities initially disclosed to the public in 2017. These flaws weaponize speculative execution, a critical performance optimization technique utilized by modern microprocessors to predict and pre-execute instructions ahead of actual program flow to maximize processing speed. When exploited maliciously, this optimization loophole tricks a processor into performing speculative operations that access sensitive data outside the authorized execution path. The attacker then infers the contents of that unauthorized data through a side-channel attack measuring cache timing variations. Spectre v2 represents a specific manifestation of this vulnerability class, abusing indirect branch prediction mechanisms inherent in modern processors. Specifically, attackers poison the CPU’s branch prediction logic to force a victim program into executing an indirect branch. This manipulation induces the processor to mispredict the branch destination and speculatively execute attacker-controlled code or an arbitrary instruction gadget. Although the physical results of these processor mispredictions are ultimately discarded by the CPU when the correct path is verified, the damage is already done. An attacker can discern what the victim’s speculative execution routines accessed by carefully monitoring microarchitectural state changes in the processor cache. Crucially, BTR zeroes in on JIT engines and stems from the intricate interplay between Self-Modifying Code and indirect branch prediction. According to the research team, this marks the first time that JIT engines have been shown to expose exploitable transient-execution opportunities directly induced by SMC. The attack model presumes an unprivileged threat actor capable of running ordinary code within a JIT engine, harboring the objective of disclosing sensitive data from the host environment. By adroitly redirecting control flow to an architecturally invalid entry point, the attacker manages to sidestep standard Spectre hardening mitigations or trigger the execution of misaligned instructions, ultimately exposing secret data. A critical prerequisite for a successful BTR attack is that the stale Branch Target Buffer entry must remain unsterilized and unreplaced after the JIT engine deallocates the original training chunk. Simultaneously, the branch predictor must subsequently select that exact same stale entry for prediction. Elaborating on the uniqueness of the technique, Cristiano Giuffrida noted in an email exchange that BTR represents the first practical instance of an in-place Spectre v2 attack, utilizing the exact same indirect branch for both the training phase and the testing phase. For years, conventional wisdom dictated that executing such an attack would be exceedingly difficult. Traditional Spectre v2 exploits rely heavily on spatial target violations, which involve hijacking an indirect branch target so that it points to a completely different location. Accomplishing this for a single branch is intuitively challenging because attackers are normally restricted to moving spatially from one valid indirect branch target to another associated with the same branch. BTR shatters this foundational assumption by demonstrating the viability of temporal Spectre v2 attacks. In this scenario, the indirect branch itself—and even its designated target—remain fundamentally identical, but the underlying meaning or semantic interpretation of that target changes dynamically as the code is rewritten. Furthermore, this newly identified variant successfully undermines existing software and hardware mitigations designed to counter this specific threat landscape, including protections introduced under the Training Solo moniker. Giuffrida emphasized that the primary limitation of BTR is its scope, which remains strictly confined to JIT environments. Because BTR bypasses spatial violations entirely, it proves that a single indirect branch paired with a single target is sufficient to mount a successful Spectre v2 attack, provided the underlying code changes its meaning in a manner controlled by the attacker. Given that contemporary operating system kernels routinely run JIT engines such as cBPF for network filtering and packet processing, the ultimate attack surface and reach of BTR are comparable to previous high-profile threats. More fundamentally, the researchers argue that BTR exposes a profound, systemic flaw in how modern microprocessors manage self-modifying and JIT-compiled code. While contemporary CPUs feature built-in hardware support to resynchronize microarchitectural structures—such as instruction and data caches whenever code is rewritten—BTR proves that these measures are fundamentally insufficient. Leaving the indirect branch prediction state stale carries severe, persistent security implications. In the wake of the responsible disclosure process, coordinated mitigations for BTR have been promptly developed and successfully merged into the mainline Linux kernel. These patches address the underlying vulnerabilities tracked under identifiers CVE-2026-64507 and CVE-2026-64508. Meanwhile, other affected software ecosystems are implementing their own defenses. GraalVM developers have acted to hinder region reuse by introducing robust randomization for JIT code-cache locations. Similarly, Mozilla engineers evaluated Indirect Branch Predictor Barrier-based mitigations for Firefox, though the organization is currently prioritizing the completion and broader deployment of architectural site isolation. Concluding their analysis, the academic researchers emphasized that the discovery of Branch Target Reuse carries major implications for the future of processor security, challenging long-held assumptions regarding microarchitectural state management and code modification. This disclosure arrives roughly two months after a separate group of researchers from MIT CSAIL—specifically Daniël Trujillo and Mengjia Yan—unveiled an alternative speculative execution attack technique known as Interrupt Injection. That method demonstrated the capability to bypass conventional Spectre v2 defenses and leak arbitrary kernel memory from both Intel- and AMD-based Linux systems, highlighting an ongoing, relentless wave of microarchitectural security research targeting modern hardware architectures. Post navigation French Tax Authority Data Breach Exposes Records of Hundreds of Thousands After Weak Security Exploited The 2026 Browser Threat Landscape: Six Critical Attack Techniques Every Security Team Must Monitor