Spectre bug is back, this time to haunt JIT engines
Researchers disclose Branch Target Reuse, a Spectre v2 JIT attack that can leak Linux root password hashes.
Researchers from Vrije Universiteit and Scuola Superiore Sant'Anna describe Branch Target Reuse, an in-place Spectre v2 attack against JIT engines that reuses stale indirect branch-prediction entries after code-cache reuse. They demonstrated proofs of concept on an Intel Linux kernel that leak the root password hash despite cBPF constant binding, at about 5.7 KB/s on Raptor Cove and 5.4 KB/s on Lion Cove. Affected engines include Linux cBPF, Oracle GraalVM, and Mozilla SpiderMonkey. Linux and Oracle deployed mitigations and CVE-2026-64507 and CVE-2026-64508 were assigned; Mozilla is prioritizing site isolation instead of a direct fix. The paper was accepted to ACM CCS 2026.