Security researchers at VUSec disclosed Branch Target Reuse (BTR), a Spectre-V2 attack targeting JIT compilers in the Linux kernel's BPF, Oracle GraalVM, and Mozilla Firefox's SpiderMonkey engine. BTR exploits stale indirect branch prediction entries to leak arbitrary memory, affecting Intel, AMD, and Arm processors. Mitigations including IBPB flushing and JIT code randomization have been deployed across affected platforms.
Branch Target Reuse (BTR) is a new Spectre-v2 attack exploiting stale branch prediction entries in JIT engines across web browsers, language runtimes, and OS kernels. The attack allows speculative control-flow hijacking by reusing obsolete code cache addresses, with demonstrated end-to-end exploits against Linux cBPF and SpiderMonkey that bypass existing mitigations.