Back to advisories

New Spectre-v2 BTR Attack Leaks Linux Memory Despite Existing Defenses

Academics disclosed Spectre-v2 BTR, a new variant that exploits JIT engines in browsers and Linux kernels to leak sensitive memory including password hashes on patched systems. This bypasses existing Spectre-v2 defenses by reusing stale branch prediction entries. Systems with JIT-enabled runtimes are at risk.

HIGHAdvisorySep 30, 2026
Action required
Monitor kernel logs and JIT runtime behavior for unusual branch prediction patterns. Escalate any suspicious memory access anomalies. Prepare for patched kernel updates when vendors release fixes. No public PoC exists yet but assume active research is underway.
Affected products
SpiderMonkeyGraalVMcBPF JITLinux kernel