Download Privacy Needle App

Type to search

Cybersecurity

New Spectre v2 Variant Targets Intel, AMD, and Arm CPUs

Share

Researchers from the VUSec group at Vrije Universiteit Amsterdam and Scuola Superiore Sant’Anna in Italy have disclosed a new variant of the Spectre v2 attack that affects systems powered by Intel, AMD, and Arm CPUs. The vulnerability, named Branch Target Reuse (BTR), targets just-in-time (JIT) compilers used by operating system kernels, web browsers, and various language runtimes.

By exploiting how processors handle code that changes during execution, an attacker capable of running code on a targeted machine could steal sensitive information from memory, such as password hashes. The researchers found that while modern CPUs restore architectural code coherence after self-modification, they do not necessarily invalidate stale indirect branch prediction entries.

Exploitation of JIT Compilers and Kernels

In JIT engines, these stale branch predictions can outlive the code they were originally created for. Once new code is written to the same memory location, the stale predictions can be reused, allowing an attacker to hijack speculative execution. This creates what the researchers describe as a speculative execute-after-free primitive.

The researchers successfully developed two end-to-end exploits against the Linux kernel. Using the classic Berkeley Packet Filter (cBPF), they demonstrated that the exploit could leak arbitrary memory on modern Intel CPUs while bypassing enabled mitigations. During demonstrations, the researchers used the attack to locate and leak a root password hash after it was loaded into memory, noting a leak rate of approximately 8 bytes per second.

Web browsers and sandboxed runtimes are also vulnerable. In Firefox, the attack could potentially be launched from a malicious website via JavaScript. While a complete browser exploit has not yet been built, the researchers found that stale branch entries persist in the SpiderMonkey JavaScript and WebAssembly engine on Intel processors long enough to be reused.

In Oracle’s GraalVM runtime, BTR could allow an attacker to speculatively skip over memory masking designed to protect the runtime’s strictest sandbox mode. Although GraalVM’s garbage collection and compilation processes often erased the stale entries before they could be exploited, the researchers noted this limitation is not fundamental.

Software Mitigations and Hardware Limitations

The researchers confirmed the behaviour on every CPU tested, including Intel, AMD, and Arm architectures. The issue stems from a lack of hardware mechanisms to keep a CPU’s branch predictor in sync with the code actually residing in memory.

CPU vendors have suggested that existing mechanisms, such as the indirect branch prediction barrier (IBPB), can mitigate BTR, but software-level implementations are required. Linux kernel developers have introduced an x86 mitigation that triggers an IBPB across every CPU core whenever a cBPF program is placed in a memory region previously used by executed BPF code.

Mozilla is currently prioritising the completion of site isolation to mitigate browser-based risks, while Oracle has already rolled out several mitigations. Regarding hardware, the researchers identified Intel’s Lion Cove as the earliest generation found to be free of this specific race condition. Other hardware protections, such as Intel’s Indirect Branch Tracking (IBT) and Arm’s Branch Target Identification (BTI), make exploitation more difficult but do not entirely eliminate the threat.

Watch Our Latest Video
Stay ahead with expert insights on privacy, cybersecurity, artificial intelligence, data protection and compliance.
No Leak, No Wahala
Published: August 16, 2026
Daily Privacy News
Cybersecurity Updates
Data Protection Tips
GDPR & NDPA Explained
Tags:
Ikeh James Certified Data Protection Officer (CDPO) | NDPC-Accredited

Ikeh James Ifeanyichukwu is a Certified Data Protection Officer (CDPO) accredited by the Institute of Information Management (IIM) in collaboration with the Nigeria Data Protection Commission (NDPC). With years of experience supporting organizations in data protection compliance, privacy risk management, and NDPA implementation, he is committed to advancing responsible data governance and building digital trust in Africa and beyond. In addition to his privacy and compliance expertise, James is a Certified IT Expert, Data Analyst, and Web Developer, with proven skills in programming, digital marketing, and cybersecurity awareness. He has a background in Statistics (Yabatech) and has earned multiple certifications in Python, PHP, SEO, Digital Marketing, and Information Security from recognized local and international institutions. James has been recognized for his contributions to technology and data protection, including the Best Employee Award at DKIPPI (2021) and the Outstanding Student Award at GIZ/LSETF Skills & Mentorship Training (2019). At Privacy Needle, he leverages his diverse expertise to break down complex data privacy and cybersecurity issues into clear, actionable insights for businesses, professionals, and individuals navigating today’s digital world.

  • 1

You Might also Like

Leave a Reply

Your email address will not be published. Required fields are marked *

  • Rating

This site uses Akismet to reduce spam. Learn how your comment data is processed.