< Back to all clusters
[TECHNOLOGY] · 5 sources

started · updated

Spectre-v2 BTR vulnerability affects Intel, AMD, and Arm CPUs

Researchers from VUSec and Scuola Superiore Sant’Anna have disclosed a new Spectre-v2 CPU vulnerability variant named Branch Target Reuse (BTR). The flaw affects Just-In-Time (JIT) engines across multiple CPU vendors, including Intel, AMD, and Arm.

BTR exploits the way modern processors handle self-modifying code. While CPUs restore architectural code coherence after modification, they may fail to invalidate stale indirect branch prediction entries. This allows attackers to hijack transient control flow to newly generated code at obsolete offsets, a phenomenon described as a “speculative execute-after-free” primitive.

The vulnerability was demonstrated against several major targets, including the Linux kernel’s cBPF JIT, Mozilla Firefox’s SpiderMonkey engine, and GraalVM. In proof-of-concept exploits against the Linux kernel, researchers successfully leaked and recovered root password hashes from a fully patched Intel system within minutes.

Entities

AMD · Intel · Kiteworks · Linux · Scuola Superiore Sant’Anna · VUSec