BTR Spectre-v2 attack exposes Linux memory through JIT engines

Researchers from VUSec and Scuola Superiore Sant’Anna have disclosed Branch Target Reuse (BTR), a new Spectre-v2 variant affecting Just-In-Time engines in web browsers, language runtimes and the Linux kernel. The researchers demonstrated two end-to-end Linux kernel exploits that recovered a root password hash within minutes on a fully patched Intel system with default protections enabled.
BTR was evaluated against Mozilla Firefox’s SpiderMonkey, GraalVM and the Linux kernel’s cBPF JIT. All three were found to be affected, although the researchers reported markedly different exploitability characteristics and leakage rates. Linux mitigations have been released and merged under CVE-2026-64507 and CVE-2026-64508.
How Branch Target Reuse works
Spectre attacks exploit speculative execution, in which processors predict and execute instructions before the outcome is known. Spectre v2 specifically abuses indirect branch prediction. A mispredicted branch can transiently execute attacker-controlled code or a useful instruction sequence; although the processor discards the architectural result, cache-state changes can reveal what data was accessed.
BTR arises from the interaction between self-modifying code and indirect branch prediction. Modern processors restore architectural code coherence after code changes, but may not invalidate stale indirect branch-prediction entries. In a JIT engine, a branch target can therefore remain in the branch target buffer after the code that created it has been freed.
The attack begins when an attacker causes a JIT engine to allocate a training chunk and directs a victim branch to it, creating a branch target buffer entry. The attacker then causes that chunk to be deallocated and a target chunk to be allocated at an address that partly reuses the old region. When the indirect branch is triggered again, the processor may select the stale entry and speculatively jump to the obsolete offset.
Why stale predictions change the risk
That transient jump can redirect control flow to an architecturally invalid entry point in newly generated code. The researchers said this can bypass Spectre hardening mitigations or reach misaligned instructions, enabling secret-data disclosure through a cache timing side channel. The technique depends on the stale entry remaining available after deallocation and being selected by the branch predictor.
The threat model requires an attacker to execute unprivileged code in a JIT engine and seek sensitive data from the host environment. That makes browser, runtime and kernel JIT behaviour relevant, rather than turning every Linux system into an immediately exploitable target without a code-execution path.
Mitigation status
Linux has incorporated mitigations for the two assigned CVEs. GraalVM hinders region reuse by randomising JIT code-cache locations. Mozilla considered mitigations based on the Indirect Branch Predictor Barrier, or IBPB, but is prioritising completion and deployment of site isolation.
For organisations, the practical implication is to track kernel updates containing CVE-2026-64507 and CVE-2026-64508, review systems that run untrusted code through JIT engines, and include browser, runtime and kernel patch status in their exposure assessment.

