New Spectre v2 Variant Targets Intel, AMD, and Arm CPUs
Share
Researchers from the VUSec group at Vrije Universiteit Amsterdam and Scuola Superiore Sant’Anna in Italy have disclosed a new variant of the Spectre v2 attack that affects systems powered by Intel, AMD, and Arm CPUs. The vulnerability, named Branch Target Reuse (BTR), targets just-in-time (JIT) compilers used by operating system kernels, web browsers, and various language runtimes.
By exploiting how processors handle code that changes during execution, an attacker capable of running code on a targeted machine could steal sensitive information from memory, such as password hashes. The researchers found that while modern CPUs restore architectural code coherence after self-modification, they do not necessarily invalidate stale indirect branch prediction entries.
Exploitation of JIT Compilers and Kernels
In JIT engines, these stale branch predictions can outlive the code they were originally created for. Once new code is written to the same memory location, the stale predictions can be reused, allowing an attacker to hijack speculative execution. This creates what the researchers describe as a speculative execute-after-free primitive.
The researchers successfully developed two end-to-end exploits against the Linux kernel. Using the classic Berkeley Packet Filter (cBPF), they demonstrated that the exploit could leak arbitrary memory on modern Intel CPUs while bypassing enabled mitigations. During demonstrations, the researchers used the attack to locate and leak a root password hash after it was loaded into memory, noting a leak rate of approximately 8 bytes per second.
Web browsers and sandboxed runtimes are also vulnerable. In Firefox, the attack could potentially be launched from a malicious website via JavaScript. While a complete browser exploit has not yet been built, the researchers found that stale branch entries persist in the SpiderMonkey JavaScript and WebAssembly engine on Intel processors long enough to be reused.
In Oracle’s GraalVM runtime, BTR could allow an attacker to speculatively skip over memory masking designed to protect the runtime’s strictest sandbox mode. Although GraalVM’s garbage collection and compilation processes often erased the stale entries before they could be exploited, the researchers noted this limitation is not fundamental.
Software Mitigations and Hardware Limitations
The researchers confirmed the behaviour on every CPU tested, including Intel, AMD, and Arm architectures. The issue stems from a lack of hardware mechanisms to keep a CPU’s branch predictor in sync with the code actually residing in memory.
CPU vendors have suggested that existing mechanisms, such as the indirect branch prediction barrier (IBPB), can mitigate BTR, but software-level implementations are required. Linux kernel developers have introduced an x86 mitigation that triggers an IBPB across every CPU core whenever a cBPF program is placed in a memory region previously used by executed BPF code.
Mozilla is currently prioritising the completion of site isolation to mitigate browser-based risks, while Oracle has already rolled out several mitigations. Regarding hardware, the researchers identified Intel’s Lion Cove as the earliest generation found to be free of this specific race condition. Other hardware protections, such as Intel’s Indirect Branch Tracking (IBT) and Arm’s Branch Target Identification (BTI), make exploitation more difficult but do not entirely eliminate the threat.




Leave a Reply