[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fzYd9c7Eb3yEG80LtAJ_ETipFjzt9o_kQaby1PAUEbFY":3},{"article":4,"iocs":50},{"id":5,"title":6,"slug":7,"summary":8,"ai_summary":9,"brief":10,"full_text":11,"url":12,"image_url":13,"published_at":14,"ingested_at":15,"relevance_score":16,"entities":17,"category_id":32,"category":33,"article_tags":37},"c234c2c7-727a-4c21-9f5f-bfed6f073570","New Spectre v2 Variant Exposes Intel, AMD, Arm CPUs to Data Leaks","new-spectre-v2-variant-exposes-intel-amd-arm-cpus-to-data-leaks-3389cc","Branch Target Reuse (BTR) is a new Spectre v2 attack targeting JIT compilers in web browsers, language runtimes, and the operating system kernel The post New Spectre v2 Variant Exposes Intel, AMD, Arm CPUs to Data Leaks appeared first on SecurityWeek.","Researchers have discovered a new Spectre v2 variant called Branch Target Reuse (BTR) that impacts Intel, AMD, and Arm processors. This vulnerability targets Just-In-Time (JIT) compilers in operating systems, browsers, and runtimes, potentially allowing attackers to steal sensitive data like password hashes by hijacking speculative execution. Exploits have been demonstrated against the Linux kernel, and attacks from malicious websites are considered feasible.","New Spectre v2 variant, Branch Target Reuse (BTR), affects Intel, AMD, and Arm CPUs, enabling data leaks.","Researchers from the VUSec group at Vrije Universiteit Amsterdam in the Netherlands and Scuola Superiore Sant’Anna in Italy have disclosed a new variant of the Spectre v2 attack that affects systems powered by Intel, AMD, and Arm CPUs. The researchers named it Branch Target Reuse (BTR), and it targets the just-in-time (JIT) compilers relied upon by operating system kernels, web browsers, and runtimes. An attacker able to run code on a targeted machine could exploit BTR to steal sensitive data from memory, such as password hashes. Attacks launched from malicious web pages also appear feasible, but the researchers have yet to build a complete browser exploit. Spectre v2 BTR exploits how processors handle code that changes at runtime. “The key insight behind the attack is that, while modern CPUs restore architectural code coherence after self-modification, they do not necessarily invalidate stale indirect branch prediction entries (i.e., branch targets),” the researchers explain. In JIT engines, these stale predictions can outlive the code they were created for. They can later be reused once new code is written to the same memory. This results in what the researchers call a speculative execute-after-free primitive, which lets an attacker hijack speculative execution into the new code at obsolete offsets. The researchers analyzed Linux cBPF, Oracle’s GraalVM runtime, and SpiderMonkey, the JavaScript and WebAssembly engine in Firefox. They developed two end-to-end exploits against the Linux kernel. Advertisement. Scroll to continue reading. Linux kernel exploit leaks the root password hash The kernel exploits abuse classic BPF (cBPF). While only privileged users can access the eBPF JIT, its more capable successor, cBPF can still be used by unprivileged programs. Seccomp, socket filtering, and packet filtering in applications like Docker and Chrome continue to rely on it. On modern Intel CPUs, the exploit leaks arbitrary memory and bypasses all enabled mitigations. According to the researchers, their exploits can extract sensitive information even when a system is fully updated and its default security settings are in place. “Our exploit leaks 8 bytes per second. That may sound slow, but with careful pointer chasing we only need to leak a small amount of data to reach the secret,” the researchers note. In a demo, they used the attack to locate and leak the root password hash after it was loaded into memory. Browsers and sandboxed runtimes are also exposed In Firefox, the attack would be launched from a malicious website that runs JavaScript code in the targeted user’s browser. Because Mozilla has yet to complete the rollout of site isolation, content from other tabs may share the attacker’s address space, exposing that data. The researchers’ proof-of-concept showed that stale branch entries persist in SpiderMonkey on Intel processors long enough to be reused. They estimate that data could leak at a rate of dozens of bytes per second, but more work is needed to build a complete browser exploit. In GraalVM, BTR could allow an attacker to speculatively skip over the memory masking that protects the runtime’s strictest sandbox mode against Spectre. The researchers managed to reliably reuse memory addresses, but GraalVM’s own code compilation and garbage collection processes erased the stale branch entries before they could be exploited. According to the researchers, this limitation “does not appear fundamental.” Fixes are left to software The issue was reported to impacted chipmakers and software developers, all of which acknowledged the research. CPU vendors pointed out that existing mechanisms, such as the indirect branch prediction barrier (IBPB), can mitigate BTR, and that fixes need to be implemented in software. Linux kernel developers have introduced an x86 mitigation that triggers an IBPB across every CPU core whenever a cBPF program is placed in a memory region that was already used by previously executed BPF code. Oracle has rolled out some mitigations, and Mozilla is currently prioritizing the completion of site isolation over IBPB-based mitigations. The researchers confirmed the underlying behavior on every CPU they tested, from Intel, AMD, and Arm. The problem stems from the fact that a CPU’s branch predictor can drift out of step with the code that is actually in memory. “No current CPU has a mechanism to keep the two in sync, so until vendors add one, your CPU is vulnerable,” they warn. Hardware control-flow protections such as x86’s IBT and Arm’s BTI protections make exploitation more difficult but do not fully remove the threat. Older Intel CPUs can still speculatively execute instructions before the check, and Lion Cove is the earliest Intel generation the researchers found to be free of this race condition. However, even on race-free CPUs, the researchers were able to bypass IBT when constant blinding was disabled, although they describe race-free IBT combined with constant blinding as a much stronger defense. SecurityWeek has reached out to Intel, AMD and Arm for comment. AMD said the researchers’ paper did not reveal a new vulnerability in its products, and noted that the technique it describes is mitigated by existing guidance for Spectre v2 attacks. Intel and ARM have not responded to the request for comment. Related: New ‘StackWarp’ Attack Threatens Confidential VMs on AMD Processors Related: New Attack Targets DDR5 Memory to Steal Keys From Intel and AMD TEEs Written By Eduard Kovacs Eduard Kovacs (@EduardKovacs) is senior managing editor at SecurityWeek. He worked as a high school IT teacher before starting a career in journalism in 2011. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering. Daily Briefing Newsletter Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights. More from Eduard Kovacs Apple Patches Zero-Day Linked to ‘Extremely Sophisticated Attack’ Nvidia Unveils AI Agent Safety Platform With Hardware-Based WatchdogCitrix Confirms 2 NetScaler Zero-Days After Admins Pulled the PlugMicrosoft SharePoint Flaw CVE-2026-65660 Now Exploited in AttacksNorth Korea Suspected in $351 Million Bitget Crypto HeistCISA Election Security Plan Flags Patching Barriers, Voter Database AttacksWindows, Linux, Android File Notification Systems Leak User ActivityOpenAI Agents Probed Websites for Vulnerabilities While Fetching Public Data Latest News DARPA Selects Xint to Use AI in Securing Military Messaging AppsRemoteThreat Launches With $7 Million for Offensive Operations PlatformReco Raises $55 Million for Agentic SecurityHackers Use ChatGPT Custom GPTs in ClickFix AttacksPentagon Personnel Agency Data Breach Impacts 3 Million PeopleRig Security Emerges From Stealth With $12M to Tackle Agentic AI Identity RisksFour Cyber Threats Harboring Big Plans for the FutureOpenAI Calls Off GPT-6.1 Astra Launch, Details Safety Cases for Frontier Training Trending Daily Briefing NewsletterSubscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts. Webinar: Securing AI Agents, MCPs, and AI Automations October 7, 2026 Learn how to address potential risks and not restrict AI adoption in your organization. See what a centralized AI gateway is and how it works in practice. Register Virtual Event: Zero Trust & Identity Strategies Summit 2026 October 14, 2026 Join as we decipher the world of zero trust and share war stories on securing an organization by eliminating implicit trust and continuously validating every stage of a digital interaction. Register People on the MoveDoppel has named Joey Rachid as Chief Security Advisor and Field Chief Information Security Officer.Delinea has appointed Timothy Regan as Chief Financial Officer.Gwen Gann has become State Chief Information Security Officer for the State of Washington a","https:\u002F\u002Fwww.securityweek.com\u002Fnew-spectre-v2-variant-exposes-intel-amd-arm-cpus-to-data-leaks\u002F","https:\u002F\u002Fwww.securityweek.com\u002Fwp-content\u002Fuploads\u002F2023\u002F08\u002FCPU-attack.jpg","2026-09-29T17:00:00+00:00","2026-09-29T18:00:51.184682+00:00",9,[18,21,23,25,28,30],{"name":19,"type":20},"SpiderMonkey","product",{"name":22,"type":20},"GraalVM",{"name":24,"type":20},"Firefox",{"name":26,"type":27},"JIT compilers","technology",{"name":29,"type":27},"Spectre v2",{"name":31,"type":27},"cBPF","80544778-fabb-4dcd-aa35-17492e5dcf4f",{"id":32,"icon":34,"name":35,"slug":36},null,"Vulnerabilities","vulnerabilities",[38,40,45],{"category":39},{"id":32,"icon":34,"name":35,"slug":36},{"category":41},{"id":42,"icon":34,"name":43,"slug":44},"89f78b1c-3503-45a1-9fc7-e23d2ce1c6d5","Malware","malware",{"category":46},{"id":47,"icon":34,"name":48,"slug":49},"e7b231c8-5f79-4465-8d38-1ef13aea5a14","Threat Intelligence","threat-intelligence",[51],{"type":52,"value":53,"context":54},"mitre_attack","T1003","Password hash dumping, demonstrated by the BTR exploit."]