Securityweek New Spectre v2 Variant BTR Exposes JIT Engines to Data Leaks
Article Content
- •The Branch Target Reuse (BTR) attack targets JIT compilers in multiple CPU architectures.
- •Exploits can leak sensitive data like root password hashes from Intel-based Linux systems.
- •Patches have been released, but the attack demonstrates the ongoing risks of speculative execution vulnerabilities.
Researchers from Vrije Universiteit Amsterdam and Scuola Superiore Sant’Anna have disclosed a new Spectre v2 variant called Branch Target Reuse (BTR), affecting JIT compilers in browsers and operating system kernels across Intel, AMD, and Arm CPUs. This attack exploits stale indirect branch prediction entries, allowing attackers to hijack speculative execution and leak sensitive data, such as root password hashes, from memory. Two proof-of-concept exploits have been demonstrated against Linux cBPF, leaking data at a rate of 8 bytes per second. The vulnerabilities have been assigned CVE-2026-64507 and CVE-2026-64508, with patches already integrated into the Linux kernel. The attack is particularly concerning as it can be executed from unprivileged code in JIT engines. The researchers have notified affected vendors, and mitigations are being assessed for performance trade-offs.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (9)
Following this threat?
Track CVE-2025-68788 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Common questions
Which systems are affected by the BTR attack?
What data can be leaked using this exploit?
Have patches been released for these vulnerabilities?
Continue Reading
Ubuntu Kernel Update Cycle Accelerated Due to AI-Driven CVE Surge Canonical has announced a shift to a unified two-week kernel release cycle for Ubuntu to address an unprecedented increase in reported vulnerabilities, primarily driven by AI-assisted bug discovery. The new schedule merges the previous four-week regular updates and two-week security patches into a weekly release…
Critical Zero-Day Exploits Target F5 and Check Point Products F5 Networks released emergency hotfixes for a critical zero-day vulnerability, CVE-2026-94127, in its BIG-IP Access Policy Manager on September 22, 2026, after confirming active exploitation. This flaw allows unauthenticated remote code execution (RCE) and has a CVSS score of 9.8. Concurrently, Check Point disclosed…