The news
On September 29, researchers from VUSec at Vrije Universiteit Amsterdam and Italy's Scuola Superiore Sant'Anna disclosed the Spectre BTR attack, a Branch Target Reuse technique that recovered a Linux root password hash within minutes from fully patched Intel systems running default protections.
Spectre attacks abuse speculative execution, the way processors guess ahead and run instructions before they know those instructions are needed, then leave traces that can be read back. BTR, which the team describes as a Spectre v2 variant, targets just-in-time (JIT) compilers, which turn code into machine instructions while a program runs. When a JIT engine frees old code and writes new code at the same memory address, the processor can keep stale predictions about where branches should jump, and briefly runs the new code from an outdated entry point.
The end-to-end exploit used unprivileged classic BPF (cBPF) programs, small filters that the Linux kernel compiles on the fly. According to BleepingComputer, the team leaked kernel memory at 8 bytes per second and recovered the root password hash from a running su process in 3 minutes on average on Intel's Raptor Cove cores and 5 minutes on Lion Cove. It also bypassed the kernel's optional constant-blinding hardening and still recovered the hash within five minutes, BleepingComputer reported.
The researchers said they confirmed the behavior on every CPU they tested, covering Intel (INTC), AMD (AMD) and Arm (ARM), BleepingComputer reported. In the SpiderMonkey JavaScript engine used by Mozilla's Firefox, stale predictions survived code reuse but did not yield a complete browser exploit. In Oracle's (ORCL) GraalVM, they found a way to speculatively skip a sandbox check, but the engine's own activity cleared the predictions before an attack finished.
Linux kernel developers merged mitigations tracked as CVE-2026-64507 and CVE-2026-64508, including a flush of branch predictions, known as an Indirect Branch Prediction Barrier (IBPB), when the BPF compiler reuses memory, according to the VUSec project page. Oracle is randomizing where GraalVM places JIT code, the researchers said, and Mozilla is prioritizing site isolation over IBPB-based fixes, SecurityWeek and The Hacker News reported. The paper was accepted at the ACM CCS 2026 security conference.
AMD told SecurityWeek the paper did not reveal a new vulnerability in its products and that existing Spectre v2 guidance mitigates the technique. Intel and Arm had not responded to SecurityWeek at publication. The researchers argue that no current processor keeps branch predictions in sync with code changes, and that "until vendors add one, your CPU is vulnerable."
The numbers
- Kernel memory leak rate (Linux cBPF exploit)
- 8 bytes per second
- Average time to recover root password hash
- 3 min (Raptor Cove), 5 min (Lion Cove)
- CPU vendors where behavior was confirmed
- Intel, AMD, Arm
- Linux kernel fixes
- CVE-2026-64507, CVE-2026-64508
Why CEOs should care
For CISOs and infrastructure leads, the key detail is the entry point: BTR needs code already running on the machine, but only as an ordinary, unprivileged user. That makes it most relevant wherever people or workloads you do not fully trust share hardware, such as multi-user Linux servers, build systems and shared hosting. Ask your teams to confirm that production and build kernels include the fixes for CVE-2026-64507 and CVE-2026-64508, and ask hosting and cloud providers in writing when their host kernels were updated.
Classic BPF is not a niche feature. SecurityWeek noted that seccomp, socket filtering and packet filtering in software such as Docker and Chrome still rely on it, so switching it off is rarely a simple option. The faster path is patching, followed by a review of which systems let untrusted users or tenants run their own code at all.
For hardware buyers and CFOs, this is not yet a reason to replace fleets. AMD disputes that the research shows anything new for its chips, Intel and Arm had not commented, and SecurityWeek reported that Lion Cove is the earliest Intel generation the researchers found free of a race condition in its branch protections. Ask each chip and server vendor which of your models are affected, whether firmware or microcode changes are planned, and what performance cost their recommended mitigations carry.
The bigger picture
Spectre-class flaws come from how modern processors are designed to be fast, so they rarely end with a single patch. BTR shows the problem moving into JIT engines, which sit inside browsers, language runtimes and the operating system kernel itself. The researchers' core point is that processors restore correct code after changes but do not always discard old predictions about that code, and current chips offer no built-in way to keep the two aligned. Boards and risk committees that marked speculative-execution risk as closed should treat it as an ongoing category that needs periodic review.
What’s next
Watch for formal guidance from Intel and Arm, for Linux distributions shipping kernels with the two fixes, and for Mozilla's site isolation work in Firefox. The full technical paper will be presented at ACM CCS 2026, which may prompt further research on other JIT engines.
What “Fact-checked” means
Fact-checking means testing a story’s facts against the evidence before it is published. This story went through at least two separate checks before this version was published.
- What we checked
- Its names, figures, dates, job titles, quotes and who said what were checked against the story’s sources, including its main source where it could be opened. The headline was checked for accuracy and overstatement.
- How
- A first check reviewed the whole story. If it passed, a second, skeptical check went back to the sources to look for mistakes in the most important facts. If a check flagged the story, it was edited to fix the problems found, and a separate re-check then reviewed the whole story again.
- Who
- The checks are made by our newsroom, as steps kept separate from the writing, under rules set by our editor, Hussein Mukhtar. A story the checks still flag is held for the editor, who decides whether it is fixed, published or dropped.
- If something is wrong
- “Fact-checked” does not mean error-free. If a material error is found after publication, we correct the story and add a note saying what changed. Report an error









