A team of cybersecurity experts from VUSec and Scuola Superiore Sant'Anna has revealed details about a new Spectre CPU vulnerability variant that impacts JIT engines in web browsers, language runtimes, and the operating system kernel across various CPU vendors. The researchers, Sander Wiebing, Yuhui Zhu, Alessandro Biondi, and Cristiano Giuffrida, explained that while modern CPUs maintain architectural code coherence after self-modification, they do not necessarily invalidate stale indirect branch prediction entries (i.e., branch targets). This allows attackers to hijack transient control flow to newly generated code at obsolete offsets, evading software hardening and bypassing misaligned gadgets.
BTR was tested against SpiderMonkey (Firefox's JIT engine), GraalVM, and the Linux kernel's cBPF JIT, all of which have been identified as affected, despite varying exploitability characteristics and leakage rates. As a proof-of-concept, two end-to-end exploits have been devised to leak and recover the root password hash within minutes on a fully patched Intel system with default protections enabled. "GraalVM hinders region reuse by randomizing JIT code-cache locations," researchers stated.
"Mozilla considered IBPB-based mitigations but is currently focusing on completing and deploying site isolation." The disclosure occurred nearly two months after MIT CSAIL researchers Daniël Trujillo and Mengjia Yan revealed an Interrupt Injection speculative execution attack technique, which can bypass Spectre v2 protections and leak arbitrary kernel memory from Intel- and AMD-based Linux systems.











