Formerly Janakpur Engineering College (JEC)Affiliated to Tribhuvan University

New Spectre variant BTR targets JIT compilers on Intel, AMD and Arm

Researchers showed that reused JIT code memory lets stale branch predictions leak data, with a working exploit against the Linux kernel's cBPF.

BCTBEI

On 1 October 2026, researchers from Vrije Universiteit Amsterdam and Italy's Scuola Superiore Sant'Anna disclosed Branch Target Reuse, a new Spectre-style attack, on the VUSec project page. It tricks a processor into running stale code predictions inside just-in-time compilers. Every Intel, AMD and Arm processor they tested behaved this way, and their Linux exploit leaked 8 bytes of memory per second.

  • 3processor makers whose chips showed the behaviour: Intel, AMD, Arm
  • 2complete exploits built against the Linux kernel
  • 2CVE identifiers assigned for the Linux fixes
  • Tens of bytesper second, the estimated leak rate in the Firefox test

What happened

The attack is called Branch Target Reuse, or BTR. It belongs to the Spectre version 2 family, a group of attacks that misuse the way processors guess where a program will jump next. According to the VUSec group at Vrije Universiteit Amsterdam, BTR targets just-in-time (JIT) compilers. These are found in web browsers, in language runtimes and in the Linux kernel. Intel's announcement credits Sander Wiebing and Cristiano Giuffrida in Amsterdam, and Yuhui Zhu and Alessandro Biondi of Scuola Superiore Sant'Anna.

The team studied three targets. The first was cBPF, the classic packet filter system inside the Linux kernel. The second was SpiderMonkey, the JavaScript and WebAssembly engine of the Firefox browser. The third was Oracle's GraalVM, a runtime that runs several programming languages. They built two complete exploits against the Linux kernel. In a demonstration, the exploit found and leaked the stored password hash of the root user, the most powerful account on a Linux system.

The researchers say the exploit leaked 8 bytes per second on modern Intel processors and bypassed all the protections that were switched on. For Firefox they built a proof of concept, a working test, with an estimated leak rate of tens of bytes per second on Intel processors. They say a complete browser attack would need more work. On GraalVM, they found the engine vulnerable, but its own activity wiped the stale predictions before they could be used. The paper will appear at the ACM Conference on Computer and Communications Security (CCS) 2026.

The engineering behind it

Modern processors do not wait to learn where a program will jump. They guess, using a hardware table called the branch target buffer, and start running instructions at the guessed address. This is called speculative execution. If the guess is wrong, the processor throws away the results. But the work it did can leave traces in the cache, and a careful attacker can measure those traces to read data they should not see. This is the general idea behind all Spectre attacks.

A JIT compiler turns frequently used code into machine instructions while the program runs. It also frees old machine code and later places new code at the same addresses. The researchers found that processors correctly update the code itself, but they do not necessarily clear the old branch predictions linked to those addresses. The old prediction survives. When the program later takes the same jump, the processor speculatively goes to where the old code used to begin, which is now the middle of new code.

The team calls this a speculative execute-after-free. The attacker first trains a jump to land in some code, then gets that code freed and replaced. The processor then uses the stale target and runs, for a short time, instructions the attacker arranged in advance. In the GraalVM case, this let the processor jump past a safety check that normally limits which memory a program can read. The researchers say no current processor has a way to keep the predictor and the code in step.

How it was fixed

The researchers reported their findings to the affected companies before publishing. They say the hardware makers replied that protection features already exist, and that BTR should be handled in software. Intel's announcement of 1 October says it does not treat BTR as a new Intel hardware vulnerability. It says its existing guidance for related Spectre version 2 problems already covers the behaviour, and it advises users to keep their operating systems up to date.

The Linux kernel developers added a fix for x86 processors. It clears the branch predictor on all cores when a cBPF program reuses a memory region that earlier code had used. Two identifiers were assigned, CVE-2026-64507 and CVE-2026-64508. Oracle made GraalVM place its compiled code at random locations, so old addresses are less likely to be reused. According to the researchers, Mozilla is focusing first on site isolation in Firefox, which keeps each website in its own separate process. The researchers advise users to install operating system and software updates as soon as they are available.

What it means in Nepal

The sources say nothing about Nepal, so this section is about the ideas and the skills. BTR is a clear case where two subjects students meet in different semesters turn out to be one problem. Branch prediction is taught in computer architecture. Memory allocation, freeing and reuse are taught in operating systems. The attack lives exactly where the two meet, and the fix was written by kernel programmers, not chip designers.

The case also shows how security research is done in practice. The team found an unexpected behaviour, built tools to measure it, tested it on processors from three companies, and then wrote working attacks to prove the risk was real. They told the companies before going public, and published their paper and code. Students who want to do research in systems or security can study this process as a model for a final-year project or a thesis.

What to study if this interests you

Computer Organization and Architecture is where branch prediction and pipelines are taught: ENCT 303 in the fifth semester of BCT, and ENEX 253 in the fourth semester of BEI. Operating System, ENCT 254, in the fourth semester of BCT, covers memory allocation and reuse, which is how stale predictions end up pointing at new code. Network and Cyber Security, ENCT 463, in the eighth semester, covers how attacks like this are found, reported and patched.

Words in this story

Speculative execution
A processor feature that runs instructions before it knows they are needed, and discards the results if the guess was wrong.
Branch target buffer
A small table inside the processor that remembers where earlier jumps went, so it can guess where the next one will go.
JIT compiler
A just-in-time compiler turns code into machine instructions while the program is running, to make it faster.
CVE
Common Vulnerabilities and Exposures, a public numbering system that gives each known security flaw its own identifier.

Where this comes from

Written in our own words; no sentence is copied from these reports. Researched with AI assistance on 11 October 2026; no member of faculty has reviewed it yet. If you spot a mistake, call 01-5091616 and we will correct it and say so.

Next story: 91,000 tSweden's hydrogen steel plant wins Google deal, then needs more cash

Last reviewed by Imperial College of Engineering. Written 11 October 2026 from the sources above.