Vulnerabilities & Exploits · Zero-Day Exploit

BTR Reuses Stale JIT Predictions for Spectre Leaks

Academic researchers from VUSec and Scuola Superiore Sant’Anna published Branch Target Reuse (BTR), a new Spectre-v2 variant that affects JIT engines in Linux, Mozilla Firefox’s SpiderMonkey, and Oracle’s GraalVM. On fully patched Intel systems, the Linux proof-of-concept can recover the root password hash in minutes.

BTR works because CPUs may keep stale indirect branch targets after code changes. When a JIT engine later repopulates that memory, the processor can be nudged into following an old prediction into new code at the wrong offset, creating a transient leak path and bypassing Spectre-v2 defenses that assume repopulated code is safe.

For kernel, browser, and runtime teams, the important map is the JIT cache, not a single application bug. If your software rewrites code at runtime, “Spectre-v2 mitigated” does not necessarily mean speculative leaks are closed, and on Linux the cBPF path gives even unprivileged filtering features a route to kernel-memory disclosure.

3 sources · 8h ago

CVE-2026-64508

NVD KEV

EPSS 0.2% (10th percentile). Microsoft patch: CBL-Mariner Releases.

CVE-2026-64507

NVD KEV

EPSS 0.2% (5th percentile). Microsoft patch: CBL-Mariner Releases.

Timeline

Sources

Part of the PlainSec briefing for 2026-09-29

Every edition of this story: BTR Reuses Stale JIT Predictions for Spectre Leaks

More from today