New Spectre v2 Variant Exposes Intel, AMD, Arm CPUs to Data Leaks
Branch Target Reuse (BTR) is a newly disclosed variant of the Spectre v2 attack affecting Intel, AMD, and Arm CPUs. It targets just-in-time (JIT) compilers used in operating system kernels, web browsers, and language runtimes. The attack exploits stale indirect branch prediction entries that persist after code modifications, enabling speculative execution attacks that can leak sensitive data such as password hashes. Researchers demonstrated exploits against the Linux kernel and browser engines like Firefox's SpiderMonkey. Mitigations require software updates, including use of indirect branch prediction barriers (IBPB). Hardware protections reduce but do not eliminate the risk. Vendors acknowledge the issue and have started rolling out mitigations, but no complete fix exists in hardware yet.
AI Analysis
Technical Summary
Branch Target Reuse (BTR) is a new Spectre v2 variant disclosed by researchers from VUSec and Scuola Superiore Sant’Anna that affects Intel, AMD, and Arm CPUs. BTR exploits the persistence of stale indirect branch prediction entries after code self-modification, particularly in JIT compilers used by OS kernels, browsers, and runtimes. This results in a speculative execute-after-free primitive allowing attackers to hijack speculative execution and leak sensitive memory data. The researchers developed exploits against Linux cBPF and Firefox’s SpiderMonkey engine, demonstrating leakage of root password hashes and potential browser-based attacks. Mitigations rely on software mechanisms like IBPB, with Linux kernel developers and Oracle implementing partial fixes. Hardware protections such as Intel’s IBT and Arm’s BTI make exploitation harder but do not fully prevent it. The issue stems from CPUs lacking mechanisms to synchronize branch predictors with code changes. AMD states existing Spectre v2 mitigations cover this technique, while Intel and Arm have not publicly commented.
Potential Impact
The BTR attack enables an attacker with code execution on a target machine to leak sensitive data from memory, including password hashes. It can bypass existing mitigations on modern Intel CPUs and affects multiple CPU vendors (Intel, AMD, Arm). The attack surface includes OS kernels, web browsers, and language runtimes that use JIT compilation. Browser-based exploitation is feasible but not yet fully demonstrated. The attack can leak data at rates sufficient to extract secrets over time. Hardware mitigations reduce but do not eliminate the risk, and software mitigations are required to mitigate the threat.
Mitigation Recommendations
Mitigations require software updates implementing indirect branch prediction barriers (IBPB) and related controls. Linux kernel developers have introduced an x86 mitigation triggering IBPB when reusing memory regions for BPF code. Oracle has deployed partial mitigations, and Mozilla is prioritizing site isolation to reduce browser exposure. Existing hardware protections (Intel IBT, Arm BTI) increase difficulty but do not fully prevent exploitation. Users and administrators should apply all available OS and runtime updates addressing this issue. Patch status is not yet fully confirmed; check vendor advisories for current guidance.
New Spectre v2 Variant Exposes Intel, AMD, Arm CPUs to Data Leaks
Description
Branch Target Reuse (BTR) is a newly disclosed variant of the Spectre v2 attack affecting Intel, AMD, and Arm CPUs. It targets just-in-time (JIT) compilers used in operating system kernels, web browsers, and language runtimes. The attack exploits stale indirect branch prediction entries that persist after code modifications, enabling speculative execution attacks that can leak sensitive data such as password hashes. Researchers demonstrated exploits against the Linux kernel and browser engines like Firefox's SpiderMonkey. Mitigations require software updates, including use of indirect branch prediction barriers (IBPB). Hardware protections reduce but do not eliminate the risk. Vendors acknowledge the issue and have started rolling out mitigations, but no complete fix exists in hardware yet.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
Branch Target Reuse (BTR) is a new Spectre v2 variant disclosed by researchers from VUSec and Scuola Superiore Sant’Anna that affects Intel, AMD, and Arm CPUs. BTR exploits the persistence of stale indirect branch prediction entries after code self-modification, particularly in JIT compilers used by OS kernels, browsers, and runtimes. This results in a speculative execute-after-free primitive allowing attackers to hijack speculative execution and leak sensitive memory data. The researchers developed exploits against Linux cBPF and Firefox’s SpiderMonkey engine, demonstrating leakage of root password hashes and potential browser-based attacks. Mitigations rely on software mechanisms like IBPB, with Linux kernel developers and Oracle implementing partial fixes. Hardware protections such as Intel’s IBT and Arm’s BTI make exploitation harder but do not fully prevent it. The issue stems from CPUs lacking mechanisms to synchronize branch predictors with code changes. AMD states existing Spectre v2 mitigations cover this technique, while Intel and Arm have not publicly commented.
Potential Impact
The BTR attack enables an attacker with code execution on a target machine to leak sensitive data from memory, including password hashes. It can bypass existing mitigations on modern Intel CPUs and affects multiple CPU vendors (Intel, AMD, Arm). The attack surface includes OS kernels, web browsers, and language runtimes that use JIT compilation. Browser-based exploitation is feasible but not yet fully demonstrated. The attack can leak data at rates sufficient to extract secrets over time. Hardware mitigations reduce but do not eliminate the risk, and software mitigations are required to mitigate the threat.
Mitigation Recommendations
Mitigations require software updates implementing indirect branch prediction barriers (IBPB) and related controls. Linux kernel developers have introduced an x86 mitigation triggering IBPB when reusing memory regions for BPF code. Oracle has deployed partial mitigations, and Mozilla is prioritizing site isolation to reduce browser exposure. Existing hardware protections (Intel IBT, Arm BTI) increase difficulty but do not fully prevent exploitation. Users and administrators should apply all available OS and runtime updates addressing this issue. Patch status is not yet fully confirmed; check vendor advisories for current guidance.
Technical Details
- Classification
- {"confidence":0.75,"severitySource":"default","classifier":"rss-v2"}
- Article Source
- {"url":"https://www.securityweek.com/new-spectre-v2-variant-exposes-intel-amd-arm-cpus-to-data-leaks/","fetched":true,"fetchedAt":"2026-09-29T17:01:16.745Z","wordCount":1569}
Threat ID: 6abbeedcc9b3d5d1770226c1
Added to database: 09/29/2026, 17:01:16 UTC
Last enriched: 09/29/2026, 17:01:22 UTC
Last updated: 09/29/2026, 18:03:47 UTC
Views: 7
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.