Branch Target Reuse: Spectre-v2 Attacks in JIT Engines
VUSec's Branch Target Reuse attack reuses stale JIT branch predictions to speculatively leak memory on Intel CPUs.
VUSec researchers present Branch Target Reuse, a Spectre-v2 attack that reuses stale indirect branch predictions after JIT code is freed and reallocated. An end-to-end Linux cBPF exploit leaks arbitrary kernel memory on modern Intel CPUs, including a root password hash from the su process, at about 8 bytes per second and bypasses enabled mitigations plus constant blinding. Proofs of concept also show speculative execution into Firefox SpiderMonkey's WebAssembly constant pool and a way to skip GraalVM sandbox masking, though those are not full end-to-end exploits.