Academics from VUSec and Scuola Superiore Sant'Anna disclosed BTR, a Spectre-v2 variant that affects Just-In-Time engines in web browsers, language runtimes and the operating system kernel across multiple CPU vendors. The mechanism is that modern processors restore architectural code coherence after self-modification but do not invalidate stale indirect branch prediction entries, so a stale target can outlive the code it pointed at and be reused when the code cache is repopulated — producing a transient execute-after-free primitive that lets an attacker hijack transient control flow to newly generated code at obsolete offsets, bypass software hardening or reach misaligned gadgets. The researchers evaluated BTR against SpiderMonkey (Mozilla Firefox's JIT), GraalVM and the Linux kernel's cBPF JIT, finding all three affected but with markedly different exploitability and leakage rates, and built two end-to-end exploits against the Linux kernel that recover the root password hash within minutes from a fully patched Intel system with default protections enabled. The result matters beyond the demo because the affected surface is the default configuration of mainstream browsers and runtimes rather than an optional component, and because the eight-year arc of Spectre-class mitigations has not closed the branch-prediction reuse path.
| Attribute | Detail |
|---|---|
| Sector | Global (Macro) |
| Date | 2026-09-30 |
| Source | The Hacker News |
| Reliability | Tier 2 |