www.securityweek.com 29 Sept 2026, 17:00 UTC

New Spectre Variant Lets Attackers Steal Memory Across CPU Platforms

New Spectre Variant Lets Attackers Steal Memory Across CPU Platforms
CyberSIXT Evidence Panel Source marked as original reporting

RESEARCHERS from the VUSec group at Vrije Universiteit Amsterdam and Italy’s Scuola Superiore Sant’Anna have revealed a new Spectre v2 variant, dubbed Branch Target Reuse (BTR), that can affect Intel, AMD, and Arm CPUs. The attack targets just-in-time (JIT) compilers used by operating systems, web browsers and runtimes, enabling an attacker who can run code on a targeted machine to exfiltrate data from memory, including sensitive items such as password hashes.

The team demonstrated end-to-end exploits against the Linux kernel and showed how malicious web pages could potentially trigger the exploit from a browser, although a full browser exploit has not yet been built.

The researchers explain that the bug lies in how modern CPUs handle self-modifying code and branch prediction: stale indirect branch predictions can outlive the code they were created for and be reused later, allowing speculative execution to access memory at obsolete offsets. In Linux, the cBPF and its predecessor eBPF are exploited to leak memory; the team reports leaking eight bytes per second in demonstrations and locating a root password hash in memory.

They also tested Firefox’s SpiderMonkey and GraalVM, finding data could be leaked at several bytes per second, though certain sandbox protections and garbage collection steps limited practical exploitation. Vendors and software maintainers say fixes lie in software mitigations, with IBPB-based barriers as a primary hardware-assisted defence.

Linux core mitigations trigger IBPB across all cores for memory regions re-used by BPF code; Oracle and Mozilla have begun applying relevant mitigations, while CPU vendors emphasise that current protections are not foolproof and software updates are required. The researchers tested Intel, AMD and Arm chips and warn that the underlying risk persists until vendors implement robust, universal remedies.

View full article

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline