
Researchers at VUSec (VU Amsterdam) and Scuola Superiore Sant’Anna have disclosed Branch Target Reuse (BTR), a new variant of the Spectre v2 speculative-execution attack. It exploits a mismatch between just-in-time (JIT) compiled code and the CPU’s branch predictor. When a JIT engine frees a block of code and places new code at the same address, the processor can still remember an indirect branch target from the old code and briefly execute the new code from that stale location. Since 2018 the field had largely assumed such self-modifying-code attacks were impractical. BTR shows they are not.
On Linux, the team used unprivileged classic BPF (cBPF) programs to train the predictor, free the original program, and drop a different one into the reused memory. The stale prediction sends the CPU to attacker-crafted instructions at a misaligned offset, leaving a measurable cache trace that lets them infer data byte by byte. They located a running su process and recovered the root password hash from its memory at about eight bytes per second. End-to-end exploits took roughly 3 minutes on Intel Raptor Cove and 5 minutes on Lion Cove, and a second exploit defeated the kernel’s constant-blinding hardening. A leaked hash is not a plaintext password; an attacker still has to crack it offline. The researchers also examined Firefox’s SpiderMonkey and Oracle’s GraalVM: stale predictions survive code reuse in SpiderMonkey, but no complete browser exploit was shown. Fixes are merged in the Linux kernel, and the flaws are tracked as CVE-2026-64507 and CVE-2026-64508.
How to check if you’re affected
Affected devices are effectively any modern computer or server: VUSec says it confirmed the underlying behavior on every Intel, AMD, and Arm CPU it tested, because no current CPU keeps the branch predictor in sync with rewritten code. The demonstrated root-hash exploit targets Intel systems running Linux with unprivileged cBPF enabled. Check that your distribution has shipped a kernel version that includes the upstream BTR fixes for CVE-2026-64507 and CVE-2026-64508, and install pending OS and firmware (microcode) updates. On multi-user Linux hosts, restricting unprivileged BPF (the kernel.unprivileged_bpf_disabled sysctl) reduces exposure, and using a strong, slow-hashed root password makes a leaked hash much harder to crack.
