New 'Spectre-BTR' CPU Flaw Bypasses Existing Protections, Puts Linux Systems at Risk
Academic researchers have revealed a new variant of the Spectre CPU vulnerability, dubbed Branch Target Reuse (BTR), which affects Just-In-Time (JIT) engines used in web browsers, programming language runtimes, and operating system kernels across multiple CPU vendors. The flaw works because modern processors do not always clear old branch prediction data after code changes, allowing attackers to trick the CPU into reusing outdated instructions in a way that leaks information.
The research team tested BTR against Mozilla Firefox's SpiderMonkey engine, GraalVM, and the Linux kernel's cBPF JIT compiler, finding all three vulnerable to varying degrees. As proof of the risk, they built working demonstrations against the Linux kernel that could extract a system's root password hash within minutes, even on a fully updated Intel machine with standard protections turned on.
Spectre-class attacks, first identified in 2017, exploit a CPU performance feature called speculative execution to access and infer sensitive data through timing side channels. This new BTR variant shows that existing defenses against Spectre v2 are not fully effective, meaning affected systems remain exposed until vendors release updated mitigations.