Security News

Spectre Strikes Again: New 'BTR' Attack Targets JIT Engines in Browsers and Runtimes

The Register · 30 Sept 2026
Key Takeaway Keep browsers, runtimes, and operating systems fully patched, as fixes for CPU speculative execution flaws like this are usually delivered through vendor software updates rather than user action.

The Spectre family of CPU vulnerabilities has resurfaced in a new form. Researchers from Vrije Universiteit in the Netherlands and Scuola Superiore Sant'Anna in Italy have identified an attack called Branch Target Reuse (BTR), described as the first practical 'in-place' Spectre v2 attack against just-in-time (JIT) compilers.

JIT engines generate machine code on the fly for browsers, runtimes and kernels. The researchers found that when this code is modified or replaced, modern CPUs restore code coherence but do not always clear out old indirect branch prediction entries. These stale entries can be reused later when the code cache is refilled, creating what the team calls a 'speculative execute-after-free' condition that can leak sensitive data. The flaw has been demonstrated in widely used JIT engines including Linux cBPF, Oracle GraalVM and Mozilla SpiderMonkey.

This discovery adds to a long list of Spectre variants uncovered since the original 2018 disclosure, showing that speculative execution vulnerabilities remain an ongoing challenge for chipmakers and software developers alike. While patches for such flaws are typically issued by CPU vendors and platform maintainers rather than end users, businesses should stay alert to vendor advisories affecting browsers, runtimes and virtualization software they rely on.

Spectre CPU vulnerability JIT engines side-channel attack patch management

Summarised by CISO AI from The Register. We link back to every original so you can read it yourself.