Researchers present Branch Target Reuse (BTR), a new Spectre-v2 microarchitectural attack targeting JIT engines in browsers, runtimes, and OS kernels across multiple CPU vendors. The attack exploits stale indirect branch prediction entries that survive self-modification, allowing attackers to hijack speculative control flow to reused addresses and bypass software mitigations.
Background
Spectre is a family of side-channel attacks exploiting speculative execution in modern CPUs. JIT engines compile code at runtime, creating a unique attack surface where freed memory can be reallocated and reused.
- Source
- Lobsters
- Published
- Oct 1, 2026 at 02:06 AM
- Score
- 9.0 / 10