Branch Target Reuse Spectre Variant Affects JIT Engines Across CPUs
Researchers from VUSec and Scuola Superiore Sant'Anna have disclosed a new Spectre-v2 variant that affects Just-In-Time (JIT) compilation engines used by web browsers, language runtimes, and operating system kernels across multiple CPU vendors.
The vulnerability, dubbed Branch Target Reuse (BTR), exploits the interaction between self-modifying code (SMC) and indirect branch prediction.
Researchers demonstrated the attack against Mozilla Firefox's SpiderMonkey JIT, GraalVM, and the Linux kernel's cBPF JIT, although the exploitability and data leakage rates differ between the affected platforms.
How Branch Target Reuse Works
Modern processors use speculative execution and branch prediction to improve performance.
BTR takes advantage of stale indirect branch prediction entries that can remain after JIT-generated code has been removed and memory is reused.
According to the researchers, CPUs restore normal architectural code behavior after self-modifying code changes, but stale branch-target information may remain in the processor's branch prediction structures.
This can allow an old branch target to be reused after the original JIT-generated code has been freed.
The resulting condition creates what researchers describe as a transient execute-after-free primitive.
BTR Attack Chain
The attack requires an attacker to be able to execute unprivileged code inside a JIT environment and attempt to extract sensitive information from the host.
The demonstrated attack follows several stages:
- The attacker causes the JIT engine to allocate a training code region.
- The victim indirect branch is trained to jump to that region.
- The corresponding branch target is stored in the CPU's Branch Target Buffer (BTB).
- The attacker forces the training region to be deallocated.
- A new target region is allocated at a partially reused address.
- The attacker triggers the same indirect branch again.
- The processor uses the stale BTB entry and speculatively jumps to the old entry point.
- The attacker gains transient control-flow manipulation that can be used to disclose sensitive data.
The stale branch target can point to an architecturally invalid location in the newly allocated code.
Researchers said this can potentially bypass some Spectre hardening mechanisms or cause the processor to execute misaligned instructions.
Linux Kernel Exploitation
As a proof of concept, researchers developed two end-to-end exploits targeting the Linux kernel.
They reported that the exploits could leak and recover a root password hash within minutes from a fully patched Intel system with default protections enabled.
The attack depends on the stale BTB entry remaining available after the original JIT code is freed and the processor selecting that stale entry during branch prediction.
Affected JIT Engines
Researchers evaluated BTR against three JIT environments:
JIT EnvironmentComponentResultMozilla FirefoxSpiderMonkeyAffectedGraalVMJIT compilerAffectedLinuxcBPF JITAffected
The researchers noted that the affected environments have significantly different exploitation characteristics and leakage rates.
Why BTR Is Different
Spectre attacks generally abuse speculative execution to cause CPUs to access data that should not be architecturally accessible.
Spectre v2 specifically abuses indirect branch prediction. An attacker can influence branch prediction so that a victim performs speculative execution along an attacker-controlled or otherwise incorrect path.
BTR introduces another element by exploiting the interaction between JIT code reuse and stale branch prediction state.
The researchers said JIT engines expose transient-execution opportunities related to self-modifying code that had not previously been demonstrated in this form.
Mitigations
Following responsible disclosure, mitigations for BTR were developed for affected software.
Linux kernel fixes have been released under:
- CVE-2026-64507
- CVE-2026-64508
GraalVM addressed the issue by randomizing JIT code-cache locations, making predictable reuse of previous JIT regions more difficult.
Mozilla considered mitigations based on Indirect Branch Predictor Barrier (IBPB) but is currently prioritizing the completion and deployment of site isolation.
Attack Requirements
BTR is not described as a simple remote vulnerability.
The attack assumes that an attacker can execute unprivileged code within a JIT environment and manipulate the allocation and reuse of JIT-generated code regions.
Successful exploitation also depends on the relevant stale BTB entry remaining available and being selected by the processor's branch predictor.
Related Spectre Research
Spectre refers to a class of CPU vulnerabilities first disclosed in 2017 involving speculative execution and microarchitectural side channels.
The new BTR research follows other recent work demonstrating techniques that can bypass existing Spectre defenses.
Earlier research disclosed Interrupt Injection, a speculative-execution technique capable of bypassing Spectre-v2 defenses and leaking kernel memory from Intel- and AMD-based Linux systems.
Key Takeaway
Branch Target Reuse (BTR) demonstrates a new way to combine JIT code reuse with stale indirect branch prediction state.
The research shows that even when software correctly handles self-modifying code at the architectural level, stale microarchitectural branch information can create additional speculative-execution risks.
Organizations should apply available updates for affected JIT environments and Linux systems and monitor future CPU and JIT security guidance related to BTR.