PunchOndo orders removal of abandoned heavy vehicles, equipment on roadsCNN TürkFransa'da grev dalgası: Ülke genelinde sokaklara döküldülerDaily MaverickROVING REPORTERS: Inside the Gauteng caves where rocks reveal the mysteries of Homo nalediThe Jerusalem PostIran receives US feedback on seven-day trust-building plan, main issue is sequencingInquirerHouse prosecution to present Duterte’s bank records within the weekCapital FMIsrael-bound flight diverted after fight between pilotsObservador DesportoPortugal regista 2.º maior número de expulsões na UEABC NewsLast US troops expected to leave Iraq on Wednesday following 12-year ISIS fightColliderThe 10 Best Slice-of-Life Books, RankedThe GuardianIsrael-bound passenger plane makes emergency landing in Saudi Arabia after reported fight between pilotsNotJustOkFor Me Lyrics by FidoStraits Times SportForever our champion: Gym pays tribute to S’porean muay thai fighter who died after bout
The Daily Newsstand · Free, Always
Wednesday, September 30, 2026

Spectre bug is back, this time to haunt JIT engines

Translate

Researchers find a way to recover stale indirect branch prediction entries

The Spectre microarchitecture vulnerability has returned yet again, this time to vex just-in-time (JIT) engines that generate machine code for browsers, runtimes, and kernels. 

The vulnerability is found in many CPUs that use speculative execution, the process of executing code before it is called to boost performance. Researchers found speculative execution opens the door to side channel attacks through which secrets can be exposed or inferred.

When news of that risk became known, chipmakers and OS developers scrambled to fix these vulnerabilities, which were referred to as Spectre and Meltdown. And since then, researchers have found two or three dozen variations, such as 2025's VMScape, one of several so-called "Spectre v2" attacks that attempt to exploit indirect branch prediction, where program control is passed indirectly by pointing to an address where the next instruction can be found rather than specifying the instruction itself.

REG AD

The attacker trains the branch predictor to execute speculatively to a chosen address in order to leak data about the microarchitecture state.

REG AD

Researchers from Vrije Universiteit in the Netherlands and Scuola Superiore Sant’Anna in Italy have revived Spectre in a form called Branch Target Reuse (BTR), which they describe as the first practical in-place Spectre v2 attack that attacks just-in-time (JIT) compilers. An in-place attack is confined to the victim's branch while an out-of-place attack relies on speculation directed toward a target on a different branch.

The researchers – Sander Wiebing, Yuhui Zhu, Alessandro Biondi, and Cristiano Giuffrida – found that this novel Spectre form can be conjured from code left in JIT engines including Linux cBPF, Oracle GraalVM, and Mozilla SpiderMonkey.

"The key insight behind the attack is that, while modern CPUs restore architectural code coherence after self-modification, they do not necessarily invalidate stale indirect branch prediction entries (i.e., branch targets)," the authors explain. "In JIT engines, these stale targets can outlive the original code and later be reused when the code cache is repopulated, yielding a speculative execute-after-free primitive."

The result is that an attacker can commandeer speculative control flow in a way that avoids some software defenses like FineIBT [PDF]. The authors showed they could exploit this flaw by designing two proof-of-concept exploits against an Intel-based Linux kernel that reveal the root password hash even with the constant binding defense provided by cBPF.

The expected leakage rate is 5.7 KB/sec for Intel Raptor Cove chips and 5.4 KB/sec for Lion Cove. It's slow but enough for an unprivileged user to coax a sensitive password hash out of a vulnerable system.

After the researchers disclosed their findings, Linux kernel developers and Oracle put mitigations in place. Two CVEs were assigned: CVE-2026-64507 and CVE-2026-64508. Mozilla, the researchers said, has opted to prioritize work on site isolation instead of addressing the issue directly. Strong mitigations like IBPB are said to be effective but add complexity and hinder performance.

The Branch Target Reuse paper has been accepted for publication at the ACM Conference on Computer and Communications Security (CCS) 2026, which will be held November 15 through 19 in The Hague, Netherlands. ®

View the original on The Register →

KioskNews shows a cleaned-up reading view extracted from the publisher’s page — the original always lives on their site, not ours.