RESEARCHERS at VUSec have released full details and proof-of-concept code for Branch Target Reuse (BTR), a Spectre-v2 variant that targets just-in-time (JIT) compilers. The end-to-end Linux kernel exploit demonstrated leaking data from kernel memory at roughly eight bytes per second, including a demonstration that walked kernel structures to obtain the root password hash.
The researchers also show proof-of-concept results against SpiderMonkey in Firefox and GraalVM, indicating the attack surface spans Linux cBPF, GraalVM’s JIT code-cache, and Firefox’s JS engine. There is no evidence of active exploitation reported in the wild at this time.
Two Linux kernel fixes have been committed to address the issue: CVE-2026-64507, which flushes the IBPB on all cores when a cBPF program reuses a previously executed JIT region, and CVE-2026-64508, which adds hardened protection against JIT spraying. In addition, Oracle has started randomising GraalVM’s JIT code-cache locations, and Mozilla is focusing on site isolation work in Firefox.
The guidance from the researchers is that while hardware mitigations such as IBPB/IBT/BTI raise the bar, they do not eliminate the risk; software patches remain essential. Patches are noted as available in the article, with the Linux kernel updates referenced by specific commit identifiers and the CVEs listed above. No exploitation in the wild has been reported, and the article emphasises updating to the patched kernel versions as patches reach distributions.