Researchers at VUSec and Scuola Superiore Sant’Anna disclosed Branch Target Reuse (BTR), a Spectre-v2-class attack that abuses stale indirect-branch predictor entries after JIT-generated code is freed and its cache region reused. The resulting speculative execute-after-free condition can redirect transient execution and expose secrets through cache side channels. Tests found the issue across evaluated Intel, AMD, and Arm CPUs and in JIT environments including Linux cBPF, Firefox SpiderMonkey, and Oracle GraalVM.
Two end-to-end exploits against Linux’s cBPF JIT leaked arbitrary kernel memory on fully patched Intel systems with default mitigations enabled, recovering a root password hash within minutes at roughly 8 bytes per second. Linux has released and backported cBPF hardening tracked as CVE-2026-64507 and CVE-2026-64508; mitigations use indirect branch prediction barriers on x86. GraalVM is randomizing JIT code-cache locations, while Mozilla is prioritizing Firefox site isolation after evaluating IBPB-based defenses. Researchers warned that existing hardware lacks a general mechanism to synchronize branch-prediction state with modified runtime code.

See affected versions and whether adversaries are exploiting it.
5 events from the most recent confirmed update back to the earliest known activity.
The researchers demonstrated two end-to-end exploits against Linux cBPF JIT that bypassed enabled mitigations on a modern Intel system with default protections. The exploits leaked arbitrary memory, including a root password hash, at approximately 8 bytes per second.
VUSec and Scuola Superiore Sant'Anna publicly disclosed BTR after the embargo lifted. The Spectre-v2-class technique was observed on tested Intel, AMD, and Arm CPUs and affects JIT implementations including Linux cBPF, Firefox SpiderMonkey, and Oracle GraalVM.
Linux added IBPB flushing when BPF JIT code is allocated in memory previously used for executed BPF code, alongside BPF JIT-spraying hardening. The mitigations were mainlined and backported to stable kernels before public disclosure, and are tracked as CVE-2026-64507 and CVE-2026-64508.
Researchers privately disclosed Branch Target Reuse (BTR) information to Linux kernel developers. BTR abuses stale indirect-branch-prediction targets after JIT code is modified or reused, creating a speculative execute-after-free primitive.
Oracle deployed mitigations including JIT code-cache randomization to hinder address-region reuse in GraalVM. Mozilla evaluated IBPB-based mitigations for SpiderMonkey but prioritized completing Firefox site isolation; researchers had shown persistent stale branch entries in SpiderMonkey but no complete browser exploit.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
4 references tracked. Mallory keeps watching after this page renders.
bleepingcomputer.com
Open sourcethehackernews.com
Open sourcesecurityweek.com
Open sourcephoronix.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.