Security researchers from VUSec and Scuola Superiore Sant'Anna have uncovered a new variant of the Spectre CPU vulnerability that can extract root password hashes from fully patched Intel-based Linux systems in minutes. The flaw, dubbed Branch Target Reuse (BTR), targets Just-In-Time (JIT) compilation engines found in web browsers, programming language runtimes, and operating system kernels across multiple processor manufacturers. Unlike earlier Spectre attacks, BTR exploits a previously unknown weakness in how modern CPUs handle dynamically generated code, bypassing existing security protections.

The vulnerability affects SpiderMonkey (Mozilla Firefox's JIT engine), GraalVM, and the Linux kernel's cBPF JIT compiler, though each shows different degrees of exploitability and data leakage speeds. As proof of the threat, researchers built two complete exploits against the Linux kernel that successfully recover root password hashes within minutes on default-configured Intel machines running current security patches. The attack works by tricking CPUs into retaining outdated indirect branch predictions even after JIT engines rewrite code, creating what researchers describe as a "transient execute-after-free primitive" that lets attackers hijack processor control flow to obsolete memory locations.

According to researchers Sander Wiebing, Yuhui Zhu, Alessandro Biondi, and Cristiano Giuffrida, "BTR targets JIT engines and arises from the interplay between Self-Modifying Code (SMC) and indirect branch prediction." The team explained that while contemporary processors restore proper code consistency after modifications, "they do not necessarily invalidate stale indirect branch prediction entries." Lead researcher Cristiano Giuffrida told The Hacker News this represents "the first example of a practical in-place Spectre-v2 attack" using the same indirect branch for both training and exploitation—a scenario previously thought impractical.

The attack sequence unfolds in three steps: an attacker first tricks the JIT engine into creating a training chunk and forces a victim branch to jump there, inserting a branch target buffer (BTB) entry. Next, the attacker causes deallocation of that training chunk and allocation of a new target chunk that partially reuses the same memory address. Finally, when the indirect branch fires again, the CPU relies on the now-obsolete BTB entry and speculatively executes code at the old entry point, allowing control-flow hijacking and secret data disclosure. The researchers note this represents "temporal" rather than "spatial" exploitation—the branch and target remain identical, but the underlying code's meaning changes in attacker-controlled ways. BTR also undermines existing Spectre v2 defenses, including protections against Training Solo vulnerabilities, because it doesn't rely on any spatial violations between different branches or targets.

Following coordinated disclosure, patches have been issued and integrated into the Linux kernel under CVE-2026-64507 and CVE-2026-64508. GraalVM has addressed the issue by randomizing JIT code-cache locations to prevent memory region reuse, while Mozilla is prioritizing site isolation deployment over immediate mitigation. The researchers identify three critical implications: in-place Spectre v2 attacks are now proven practical in the temporal domain, JIT engines must deploy either isolation mechanisms or specific BTR countermeasures, and modern CPUs fail to resynchronize all necessary internal state when code gets rewritten—suggesting similar vulnerabilities may surface in the future. The disclosure arrives roughly two months after MIT researchers revealed another speculative execution technique called Interrupt Injection that circumvents Spectre v2 defenses on Intel and AMD Linux systems. Organizations relying on JIT-based systems may need to reassess their security postures as processor-level vulnerabilities continue evolving faster than hardware vendors can redesign silicon. The recurring pattern suggests a fundamental architectural tension between performance optimization and security that won't resolve through software patches alone.