Part of a story covered by 4 sources: “Branch Target Reuse Spectre-v2 Variant Leaks Kernel Memory” — merged summary and timeline →
Branch Target Reuse: Practical Spectre-v2 Attacks in JIT Engines via Stale Branch Prediction Entries
AI summary · grok-4.7
VUSec disclosed Branch Target Reuse, a practical Spectre-v2 attack on JIT engines via stale branch-prediction entries.
VUSec announced Branch Target Reuse (BTR), a Spectre-v2 technique that uses stale branch-prediction entries to attack JIT engines. The disclosure points to a CCS 2026 paper, a project page, and a public GitHub repository. The oss-security note mentions mitigations but does not assign a CVE or report exploitation observed in the wild.
- VUSec published Branch Target Reuse, a Spectre-v2 technique against JIT engines.
- Attacks reuse stale branch-prediction entries rather than injecting new ones.
- A CCS 2026 paper, project page, and GitHub repository were released.
- The post references mitigations but names no CVE or in-the-wild exploitation.
OrganizationsVUSec
Full article
Posted by Alan Coopersmith on Sep 29 https://www.vusec.net/projects/btr/ was announced today: https://download.vusec.net/papers/btr_ccs26.pdf https://github.com/vusec/btr As for mitigations:
This source does not provide full text. Read it at seclists.org.