Stale branch predictions reopen Spectre in browser JIT engines

Researchers show a practical Spectre v2 variant that harvests stale branch predictions left behind by just-in-time compilers.

CSBadmin
1 Min Read

Spectre is back, and this time the target is the just-in-time compilers that turn code into machine instructions inside browsers and runtimes.

Researchers from Vrije Universiteit Amsterdam and Italy’s Scuola Superiore Sant’Anna describe an in-place Spectre v2 attack they call Branch Target Reuse. Their insight: when a JIT engine rewrites code, modern CPUs restore architectural coherence but leave stale entries in the indirect branch predictor.

Those leftover targets can outlive the code they pointed to. Once a JIT code cache refills, the old entry gets reused, handing an attacker a speculative execute-after-free primitive. The team says it slips past software defenses such as FineIBT.

They built proof-of-concept exploits against an Intel-based Linux kernel that surfaced a root password hash even with constant binding active in Linux cBPF. Leakage runs about 5.7 KB per second on Raptor Cove chips and 5.4 KB on Lion Cove, modest but enough for an unprivileged user to drain a secret.

The same weakness touches Oracle GraalVM and Mozilla SpiderMonkey. Kernel developers and Oracle have shipped mitigations, and two bugs were assigned, CVE-2026-64507 and CVE-2026-64508. Mozilla is instead leaning on site isolation. IBPB helps but carries a performance cost.

CSBadmin

The latest in cybersecurity news and updates.

Share This Article
Follow:
The latest in cybersecurity news and updates.