New Spectre v2 Variant Exposes Intel, AMD, Arm CPUs to Data Leaks
New Spectre-v2 variant BTR lets attackers leak arbitrary memory, including root password hashes, from Intel, AMD, and Arm systems via stale JIT branch predictions.
VUSec and Scuola Superiore Sant'Anna researchers disclosed Branch Target Reuse (BTR), a Spectre-v2 variant exploiting stale branch predictor entries left by self-modifying JIT code. End-to-end exploits against the Linux kernel's unprivileged cBPF JIT leak arbitrary memory at 8 bytes per second, recovering the root password hash on fully updated Intel systems with default mitigations enabled. Linux shipped an IBPB-based x86 mitigation, Oracle partially mitigated GraalVM via code-cache randomization, Mozilla is prioritizing site isolation, and AMD says existing Spectre-v2 guidance applies.