Skip to content
New Spectre v2 Variant BTR Exposes JIT Engines to Data Leaks

New Spectre v2 Variant BTR Exposes JIT Engines to Data Leaks

First seen 29 Sep 2026, 19:12 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •September 30, 2026 at 18:35 UTC
  • •The Branch Target Reuse (BTR) attack targets JIT compilers in multiple CPU architectures.
  • •Exploits can leak sensitive data like root password hashes from Intel-based Linux systems.
  • •Patches have been released, but the attack demonstrates the ongoing risks of speculative execution vulnerabilities.

Researchers from Vrije Universiteit Amsterdam and Scuola Superiore Sant’Anna have disclosed a new Spectre v2 variant called Branch Target Reuse (BTR), affecting JIT compilers in browsers and operating system kernels across Intel, AMD, and Arm CPUs. This attack exploits stale indirect branch prediction entries, allowing attackers to hijack speculative execution and leak sensitive data, such as root password hashes, from memory. Two proof-of-concept exploits have been demonstrated against Linux cBPF, leaking data at a rate of 8 bytes per second. The vulnerabilities have been assigned CVE-2026-64507 and CVE-2026-64508, with patches already integrated into the Linux kernel. The attack is particularly concerning as it can be executed from unprivileged code in JIT engines. The researchers have notified affected vendors, and mitigations are being assessed for performance trade-offs.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Timeline

2026-07-25
CVE-2026-64507 published
Vulnerability affecting JIT engines disclosed, with patches integrated into the Linux kernel.
BleepingComputer
2026-07-25
CVE-2026-64508 published
Another vulnerability related to the BTR attack disclosed, affecting similar systems.
BleepingComputer
2026-09-25
CVE-2026-65660 added to CISA KEV
CISA added the BTR vulnerability to its Known Exploited Vulnerabilities catalog due to active exploitation.
Securityweek

More articles in this cluster (9)

Following this threat?

Track CVE-2025-68788 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed

Common questions

Which systems are affected by the BTR attack?
The BTR attack affects JIT compilers in systems using Intel, AMD, and Arm CPUs, particularly those running Linux.
What data can be leaked using this exploit?
The exploit can leak sensitive information such as root password hashes from memory.
Have patches been released for these vulnerabilities?
Yes, patches have been integrated into the Linux kernel for the identified vulnerabilities.