New Spectre Variant Targets JIT Compilers Via Branch Target Reuse
New Spectre variant hits JIT compilers, leaking password hashes on Intel-based Linux systems, researchers say.
The report comes from the Vrije Universiteit in the Netherlands and Scuola Superiore Sant’Anna in Italy. It describes how modern processors use speculative execution and branch prediction, including the Branch Target Buffer, to remember recurring branch targets. JIT compilers create code at a memory address and run it repeatedly, and the CPU learns to jump to that address. When the JIT deletes the code and places something else at the same address, the CPU may still try to jump there first. That behavior is Branch Target Reuse, and researchers exploited the moment before the processor corrects itself.
BTR is dangerous because no new malware is needed, according to the report. Machine-code bytes can mean different things when execution begins at a different byte offset. The researchers built two proof-of-concept exploits against Intel-based Linux kernels and said they could reveal the root password hash even with the constant binding defense provided by cBPF. They measured expected leakage rates of 5.7 KB/sec on Intel Raptor Cove chips and 5.4 KB/sec on Lion Cove chips. The Register described the rate as slow but enough for an unprivileged user to coax a sensitive password hash out of a vulnerable system.
Linux kernel developers and Oracle responded with mitigations, and the bugs received CVE-2026-64507 and CVE-2026-64508. Mozilla chose to focus more on site isolation, according to the report. The researchers said IBPB is most likely effective but will slow the machine down. 'Update your OS and software as soon as vendor patches are available,' the researchers said. 'Both the Linux kernel and Oracle have released patches.'
Spectre and Meltdown emerged in 2017 when researchers showed that speculative execution could be abused through side-channel attacks. Because the flaws affected virtually all chips, the industry rushed software patches; some succeeded, but many chips were throttled significantly and some computers were entirely bricked, according to the report. Variants have continued to appear since then.
The Branch Target Reuse paper was peer-reviewed and accepted by ACM CCS 2026, a major academic cybersecurity conference scheduled for mid-November 2026 in The Hague, Netherlands.