{
  "id": 10881445,
  "title": "Spectre bug is back, this time to haunt JIT engines",
  "url": "https://urgent.news/2026/09/30/spectre-bug-is-back-this-time-to-haunt-jit-engines",
  "topic": "science",
  "section": "Science",
  "published": "2026-09-30T07:01:00.000Z",
  "source": {
    "name": "The Register Science",
    "slug": "the-register-science",
    "url": "https://www.theregister.com/security/2026/09/30/spectre-bug-is-back-this-time-to-haunt-jit-engines/5299937"
  },
  "original_language": "en",
  "account": "The Spectre microarchitectural flaw has resurfaced, this time targeting just-in-time (JIT) compilers in CPUs that utilize speculative execution. Researchers from Vrije Universiteit in the Netherlands and Scuola Superiore Sant’Anna in Italy have devised an in-place attack called Branch Target Reuse (BTR), which exploits indirect branch prediction to leak data about the microarchitecture. Unlike out-of-place attacks, BTR confines its malicious activity to the victim's branch, making it a potentially more practical threat. The attack capitalizes on the fact that modern CPUs restore architectural code coherence after self-modification but fail to invalidate stale indirect branch prediction entries. In JIT engines, these stale entries can survive the original code and be reused during cache repopulation, creating a speculative execute-after-free primitive. The researchers demonstrated this vulnerability by crafting two proof-of-concept exploits that successfully revealed the root password hash on an Intel-based Linux kernel, even with cBPF's constant binding defense. While mitigations have been implemented, strong defenses like IBPB add complexity and negatively impact performance. Mozilla has chosen to prioritize site isolation instead of directly addressing the issue. The Branch Target Reuse attack has been published at the ACM Conference on Computer and Communications Security (CCS) 2026, set to take place from November 15 to 19 in The Hague, Netherlands.",
  "summary": "Researchers find a way to recover stale indirect branch prediction entries",
  "key_points": [
    "Spectre bug resurfaces, targeting JIT compilers",
    "Branch Target Reuse (BTR) attack exploits indirect branch prediction",
    "Proof-of-concept exploits leak root password hash on Intel-based Linux kernel"
  ],
  "editors_take": "The reappearance of the Spectre flaw in JIT engines means that despite existing mitigations, CPUs remain vulnerable to data-leaking attacks that can be executed with relative practicality and minimal complexity.",
  "illustration": null,
  "coverage": {
    "outlets": 2,
    "also_reported_by": [
      {
        "outlet": "The Register",
        "title": "Spectre bug is back, this time to haunt JIT engines",
        "url": "https://urgent.news/2026/09/30/spectre-bug-is-back-this-time-to-haunt-jit-engines-10883498",
        "published": "2026-09-30T07:01:00.000Z"
      }
    ]
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}