Endpoint Security

New Spectre v2 Variant Exposes Intel, AMD, Arm CPUs to Data Leaks

Branch Target Reuse (BTR) is a new Spectre v2 attack targeting JIT compilers in web browsers, language runtimes, and the operating system kernel

CPU patches

Researchers from the VUSec group at Vrije Universiteit Amsterdam in the Netherlands and Scuola Superiore Sant’Anna in Italy have disclosed a new variant of the Spectre v2 attack that affects systems powered by Intel, AMD, and Arm CPUs.

The researchers named it Branch Target Reuse (BTR), and it targets the just-in-time (JIT) compilers relied upon by operating system kernels, web browsers, and runtimes.

An attacker able to run code on a targeted machine could exploit BTR to steal sensitive data from memory, such as password hashes. Attacks launched from malicious web pages also appear feasible, but the researchers have yet to build a complete browser exploit.

Spectre v2 BTR exploits how processors handle code that changes at runtime. “The key insight behind the attack is that, while modern CPUs restore architectural code coherence after self-modification, they do not necessarily invalidate stale indirect branch prediction entries (i.e., branch targets),” the researchers explain.

In JIT engines, these stale predictions can outlive the code they were created for. They can later be reused once new code is written to the same memory. This results in what the researchers call a speculative execute-after-free primitive, which lets an attacker hijack speculative execution into the new code at obsolete offsets.

The researchers analyzed Linux cBPF, Oracle’s GraalVM runtime, and SpiderMonkey, the JavaScript and WebAssembly engine in Firefox. They developed two end-to-end exploits against the Linux kernel. 

Advertisement. Scroll to continue reading.

Linux kernel exploit leaks the root password hash

The kernel exploits abuse classic BPF (cBPF). While only privileged users can access the eBPF JIT, its more capable successor, cBPF can still be used by unprivileged programs. Seccomp, socket filtering, and packet filtering in applications like Docker and Chrome continue to rely on it.

On modern Intel CPUs, the exploit leaks arbitrary memory and bypasses all enabled mitigations. According to the researchers, their exploits can extract sensitive information even when a system is fully updated and its default security settings are in place.

“Our exploit leaks 8 bytes per second. That may sound slow, but with careful pointer chasing we only need to leak a small amount of data to reach the secret,” the researchers note. In a demo, they used the attack to locate and leak the root password hash after it was loaded into memory.

Browsers and sandboxed runtimes are also exposed

In Firefox, the attack would be launched from a malicious website that runs JavaScript code in the targeted user’s browser. Because Mozilla has yet to complete the rollout of site isolation, content from other tabs may share the attacker’s address space, exposing that data.

The researchers’ proof-of-concept showed that stale branch entries persist in SpiderMonkey on Intel processors long enough to be reused. They estimate that data could leak at a rate of dozens of bytes per second, but more work is needed to build a complete browser exploit.

In GraalVM, BTR could allow an attacker to speculatively skip over the memory masking that protects the runtime’s strictest sandbox mode against Spectre. The researchers managed to reliably reuse memory addresses, but GraalVM’s own code compilation and garbage collection processes erased the stale branch entries before they could be exploited. According to the researchers, this limitation “does not appear fundamental.”

Fixes are left to software

The issue was reported to impacted chipmakers and software developers, all of which acknowledged the research. CPU vendors pointed out that existing mechanisms, such as the indirect branch prediction barrier (IBPB), can mitigate BTR, and that fixes need to be implemented in software.

Linux kernel developers have introduced an x86 mitigation that triggers an IBPB across every CPU core whenever a cBPF program is placed in a memory region that was already used by previously executed BPF code.

Oracle has rolled out some mitigations, and Mozilla is currently prioritizing the completion of site isolation over IBPB-based mitigations.

The researchers confirmed the underlying behavior on every CPU they tested, from Intel, AMD, and Arm. 

The problem stems from the fact that a CPU’s branch predictor can drift out of step with the code that is actually in memory. “No current CPU has a mechanism to keep the two in sync, so until vendors add one, your CPU is vulnerable,” they warn.

Hardware control-flow protections such as x86’s IBT and Arm’s BTI protections make exploitation more difficult but do not fully remove the threat. Older Intel CPUs can still speculatively execute instructions before the check, and Lion Cove is the earliest Intel generation the researchers found to be free of this race condition.

However, even on race-free CPUs, the researchers were able to bypass IBT when constant blinding was disabled, although they describe race-free IBT combined with constant blinding as a much stronger defense.

SecurityWeek has reached out to Intel, AMD and Arm for comment. AMD said the researchers’ paper did not reveal a new vulnerability in its products, and noted that the technique it describes is mitigated by existing guidance for Spectre v2 attacks.

Intel and ARM have not responded to the request for comment.

Related: New ‘StackWarp’ Attack Threatens Confidential VMs on AMD Processors

Related: New Attack Targets DDR5 Memory to Steal Keys From Intel and AMD TEEs

Related Content

Cybercrime

In the wake of a suspected leader’s arrest, ShinyHunters says it never intended to publish data stolen from the FBI.

Data Protection

Researchers show that file-change notification systems can leak keystroke timing, browsing activity, and WhatsApp media events.

Data Breaches

The cybercrime group is unhappy with its description in an FBI report and threatens to leak stolen information. 

Data Breaches

Revolut allegedly fed customer information to hackers impersonating an Italian government agency for five months.

Data Breaches

A hacker claims to have stolen 7.5 million customer records after breaching the company’s systems.

Vulnerabilities

Major chipmakers announced patches for vulnerabilities recently discovered in their products.

Cloud Security

A threat actor is claiming the exfiltration of millions of records from McDonald’s, TCS, Vodafone, and other large organizations.

Data Breaches

The hackers published the allegedly stolen information, including names, addresses, email addresses, and phone numbers.

Copyright © 2026 SecurityWeek ®, a Wired Business Media Publication. All Rights Reserved.

Exit mobile version