freenode
Security & Cryptography

Branch Target Reuse brings Spectre-v2 back to JIT engines

VUSec shows stale branch predictors can turn code-cache reuse into speculative execute-after-free across kernel BPF, GraalVM, and Firefox.

Researchers at VUSec have disclosed Branch Target Reuse (BTR), a Spectre-v2 variant that turns just-in-time compilation into a practical speculative control-flow hijack. The attack hits JIT engines in browsers, language runtimes, and the operating system kernel, and the team demonstrated end-to-end exploits against the Linux kernel on multiple CPU vendors.

Modern processors restore architectural coherence after self-modifying code, but they do not always flush stale indirect branch prediction entries. In a JIT, those entries can outlive the original code. When the code cache is later repopulated, a predictor may still steer speculative execution to an obsolete offset inside newly generated code. The result is a speculative execute-after-free: attackers can reach misaligned gadgets or bypass software hardening that assumed the old layout was gone.

VUSec analyzed Linux classic BPF, Oracle GraalVM, and SpiderMonkey (Firefox). According to The Hacker News, the Linux proofs of concept recovered a root password hash within minutes on a fully patched Intel system.

Kernel developers have already landed mitigations. CVE-2026-64507 covers an x86 change that issues an IBPB flush on all cores whenever a cBPF program reuses a previously executed BPF JIT region; CVE-2026-64508 covers related BPF hardening that discourages such reuse as an optimization. The IBPB path applies whether or not Indirect Branch Tracking is enabled. GraalVM instead randomizes JIT code-cache locations to hinder reuse. Mozilla weighed IBPB-style fixes but is currently prioritizing broader site isolation.

BTR shows that Spectre-v2 defenses remain incomplete wherever software freely reuses executable regions that branch predictors still remember.