Spectre bug is back, this time to haunt JIT engines
Researchers find a way to recover stale indirect branch prediction entries
The Spectre microarchitectural flaw has resurfaced, this time targeting just-in-time (JIT) compilers in CPUs that utilize speculative execution. Researchers from Vrije Universiteit in the Netherlands and Scuola Superiore Sant’Anna in Italy have devised an in-place attack called Branch Target Reuse (BTR), which exploits indirect branch prediction to leak data about the microarchitecture.
Unlike out-of-place attacks, BTR confines its malicious activity to the victim's branch, making it a potentially more practical threat. The attack capitalizes on the fact that modern CPUs restore architectural code coherence after self-modification but fail to invalidate stale indirect branch prediction entries. In JIT engines, these stale entries can survive the original code and be reused during cache repopulation, creating a speculative execute-after-free primitive.
The researchers demonstrated this vulnerability by crafting two proof-of-concept exploits that successfully revealed the root password hash on an Intel-based Linux kernel, even with cBPF's constant binding defense. While mitigations have been implemented, strong defenses like IBPB add complexity and negatively impact performance.
Mozilla has chosen to prioritize site isolation instead of directly addressing the issue. The Branch Target Reuse attack has been published at the ACM Conference on Computer and Communications Security (CCS) 2026, set to take place from November 15 to 19 in The Hague, Netherlands.
Written by urgent.news from The Register Science's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.
Also reported by 1 other outlet
- Spectre bug is back, this time to haunt JIT engines theregister.com