Find notable cyber news and cases, enriched with sources, timelines, and signals.

JIT engines Branch Target Reuse (BTR) (multiple vulnerabilities)

Vulnerability
First reported
Last updated
Happening score
H score 36
2 unique sources, 2 articles

Summary

Hide ▲

Researchers disclosed Branch Target Reuse (BTR), a new Spectre-v2 vulnerability variant that targets JIT engines in web browsers, language runtimes, and the Linux kernel. Evaluations found the flaw in SpiderMonkey, GraalVM, and the kernel's cBPF JIT across multiple CPU vendors. Two kernel proof-of-concept exploits recovered a root password hash within minutes on a fully patched Intel system, and mitigations were merged for CVE-2026-64507 and CVE-2026-64508.

Related Happenings

DDRop active interposer attack analysis on DDR5 confidential-computing memory protection

Technical Analysis
H score10 First: 14.09.2026 19:58 Last: 14.09.2026 19:58 Sources 1

About this happening: Researchers disclosed DDRop, a hardware interposer attack that breaks Intel TDX and AMD SEV-SNP memory protection on DDR5 cloud servers, letting stale encrypte...

Intel TDX and AMD SEV-SNP freshness gap security flaw

Vulnerability
H score11 First: 14.09.2026 19:58 Last: 14.09.2026 19:58 Sources 1

About this happening: A freshness flaw in Intel TDX and AMD SEV-SNP lets a DDR5 interposer attack make stale encrypted memory look current, undermining confidential-computing integrity....

INTERRUPT INJECTION TONTOU analysis bypassing Spectre v2 defenses on Linux

Technical Analysis
H score24 First: 06.08.2026 19:17 Last: 06.08.2026 19:17 Sources 1

About this happening: MIT CSAIL researchers disclosed INTERRUPT INJECTION, a TONTOU timing primitive that can bypass Spectre v2 defenses on Linux by using unprivileged code to s...

Linux kernel Dirty Frag local root escalation privilege-escalation flaw

Vulnerability
H score30 First: 08.05.2026 10:45 Last: 08.05.2026 10:45 Sources 1

About this happening: Dirty Frag is a newly disclosed Linux kernel zero-day that can give local attackers root privileges on most major Linux distributions. The flaw is anchored in the...

Timeline

  1. 29.09.2026 20:00 2 articles · 1h ago

    Researchers disclose Branch Target Reuse Spectre-v2 flaw

    Initial Disclosure

    VUSec and Scuola Superiore Sant'Anna disclosed Branch Target Reuse (BTR), a new Spectre-v2 variant that targets Just-In-Time (JIT) engines in web browsers, language runtimes, and the Linux kernel across multiple CPU vendors. SpiderMonkey, GraalVM, and the Linux kernel's cBPF JIT were identified as affected.

    Show sources
  2. 29.09.2026 20:00 1 articles · 1h ago

    Branch Target Reuse reuses stale branch targets in JIT engines

    Technical Analysis Update

    BTR exploits the interaction between self-modifying code and indirect branch prediction: modern CPUs may preserve stale indirect branch targets after code changes, letting a repopulated JIT cache reuse old targets and create a transient execute-after-free primitive. The technique can hijack transient control flow to newly generated code at obsolete offsets and bypass software hardening or reach misaligned gadgets.

    Show sources
  3. 29.09.2026 20:00 1 articles · 1h ago

    Linux kernel proof-of-concept exploits recover a root password hash

    Victim Impact Update

    Two end-to-end exploits against the Linux kernel showed that BTR can leak and recover the root password hash within minutes on a fully patched Intel system with default protections enabled. The attack requires unprivileged code execution inside a JIT engine and can disclose sensitive host data through speculative control-flow hijacking.

    Show sources
  4. 29.09.2026 20:00 1 articles · 1h ago

    Linux kernel mitigations are merged for CVE-2026-64507 and CVE-2026-64508

    Mitigation Patch Update

    Following responsible disclosure, Linux kernel mitigations for CVE-2026-64507 and CVE-2026-64508 were released and merged. The researchers also noted that GraalVM randomizes JIT code-cache locations to hinder region reuse, while Mozilla prioritized site isolation over IBPB-based mitigations.

    Show sources