Spectre bug is back, this time to haunt JIT engines
Researchers find a way to recover stale indirect branch prediction entries
The Spectre microarchitecture flaw has reemerged, this time posing a threat to just-in-time (JIT) compilers found in various software systems. Speculative execution, a technique used to enhance performance, inadvertently creates an avenue for side-channel attacks that can expose or infer sensitive information. Upon discovery, chip manufacturers and operating system developers rushed to patch the vulnerabilities, previously known as Spectre and Meltdown.
Since then, numerous variations have surfaced, including 2025 s VMScape, an iteration of what is known as Spectre v2. This variant aims to exploit indirect branch prediction, a method where program control is indirectly granted by pointing to an address where the next instruction is stored. Researchers from Vrije Universiteit and Scuola Superiore Sant’Anna have reinvigorated Spectre in a novel form called Branch Target Reuse (BTR), which they assert is the first genuinely practical in-place Spectre v2 attack targeting JIT compilers.
An in-place attack is limited to the victim's branch, while an out-of-place attack speculatively targets a branch on a different path. The researchers, led by Sander Wiebing, Yuhui Zhu, Alessandro Biondi, and Cristiano Giuffrida, discovered that this unique Spectre form can be generated from code residing within JIT engines, such as Linux cBPF, Oracle GraalVM, and Mozilla SpiderMonkey.
The core insight behind the attack lies in the fact that, while modern CPUs restore architectural code coherence following self-modification, they do not necessarily invalidate stale indirect branch prediction entries. In JIT engines, these obsolete targets can persist beyond their original code and potentially be reused when the code cache is replenished, creating a speculative execute-after-free primitive.
This allows an attacker to manipulate speculative control flow, evading certain software defenses like FineIBT. The researchers demonstrated their exploit by crafting two proof-of-concept attacks against an Intel-based Linux kernel, successfully revealing the root password hash, even with the safeguards provided by cBPF. Although the leakage rate is slow, at 5.7 KB/sec for Intel Raptor Cove chips and 5.4 KB/sec for Lion Cove, it is sufficient for an unprivileged user to extract sensitive password hashes from a vulnerable system.
Following the disclosure of their findings, Linux kernel developers and Oracle promptly implemented mitigations. Two CVEs, CVE-2026-64507 and CVE-2026-64508, were assigned. Mozilla, however, chose to prioritize site isolation over addressing the issue directly. Strong mitigations like IBPB are deemed effective but may introduce complexity and negatively impact performance.
The Branch Target Reuse paper has been accepted for publication at the ACM Conference on Computer and Communications Security (CCS) 2026, scheduled to take place from November 15 to 19 in The Hague, Netherlands.
Written by urgent.news from The Register's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.
This story
This is one outlet's version. Read the fullest account.
- Spectre bug is back, this time to haunt JIT engines theregister.com