New Spectre v2 Variant Exposes Intel, AMD, Arm CPUs to Data Leaks
Researchers at VUSec and Scuola Superiore Sant'Anna disclosed Branch Target Reuse (BTR), a Spectre v2 variant that exploits stale indirect branch predictions in JIT compilers. Linux kernel exploits leak 8 bytes per second and can extract the root password hash even on fully patched systems with default mitigations enabled.
- BTR abuses stale indirect branch prediction entries in JIT engines
- Linux kernel exploit leaks 8 bytes per second, bypassing all mitigations on Intel
- Linux cBPF, GraalVM and Firefox's SpiderMonkey are affected; AMD and Arm also impacted
- Fixes fall to software: Linux added an IBPB mitigation, Oracle and Mozilla are working on theirs
Read next
AI