{
  "id": 10945577,
  "title": "Notorious Spectre CPU vulnerability returns hitting JIT engines via side channel attacks",
  "url": "https://urgent.news/2026/09/30/notorious-spectre-cpu-vulnerability-returns-hitting-jit-engines-via",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-09-30T12:55:00.000Z",
  "source": {
    "name": "TechRadar",
    "slug": "techradar",
    "url": "https://www.techradar.com/pro/security/notorious-spectre-cpu-vulnerability-returns-hitting-jit-engines-via-side-channel-attacks"
  },
  "original_language": "en",
  "account": "A new variant of the infamous Spectre vulnerability has emerged, targeting just-in-time (JIT) compilers in Intel-based Linux systems. Security researchers from the Vrije Universiteit in the Netherlands and Scuola Superiore Sant’Anna in Italy have demonstrated a practical attack known as Branch Target Reuse (BTR), which exploits the processor's prediction behavior. This attack, labeled as the first practical in-place Spectre v2 attack, targets JIT compilers and stores memory addresses in the Branch Target Buffer (BTB) during code execution. When JIT deletes the code and replaces it with new instructions at the same address, the CPU continues to try to jump to the old address, allowing the researchers to exploit the momentary discrepancy. The attack does not require new malware, as machine-code bytes can mean different things depending on the byte offset when execution begins. Two proof-of-concept exploits were developed, targeting Intel-based Linux kernels, enabling the theft of sensitive information such as root password hashes. Mitigations have been released by Linux kernel developers and Oracle, but the leaks have earned two CVEs: CVE-2026-64507 and CVE-2026-64508. Mozilla is focusing on site isolation, while Intel's Intel Processor Branch Prediction Buffer (IBPB) may slow down the machine. Experts recommend updating OS and software as soon as vendor patches are available. The research, peer-reviewed and accepted by the ACM CCS 2026 conference, will be presented in mid-November at the Hague, Netherlands.",
  "summary": "Branch Target Reuse is the latest application of the dreaded Spectre flaw.",
  "key_points": [],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}