Researchers from VUSec and Scuola Superiore Sant'Anna unveiled a new Spectre-v2 variant called Branch Target Reuse (BTR) that bypasses existing CPU speculative execution defenses and leaks sensitive data from Linux kernel memory.

The attack exploits a fundamental flaw in how modern processors predict branch targets within Just-In-Time (JIT) compilation engines. JIT engines power web browsers like Chrome and Firefox, language runtimes such as Python and Node.js, and Linux kernels themselves. BTR works by reusing previously cached branch targets to speculate on code execution paths, allowing attackers to read protected memory regions despite existing Retpolines and other branch prediction isolation defenses.

Unlike previous Spectre-v2 attacks, BTR operates across multiple CPU vendors and does not require direct control over branch predictor entries. Instead, it leverages the inherent behavior of branch target prediction mechanisms that remain accessible to unprivileged code. This makes the attack considerably more practical and widely deployable than earlier variants.

The vulnerability represents a direct challenge to defenses deployed since the original Spectre disclosure in 2018. Retpolines, the primary mitigation technique recommended by Intel and adopted across major operating systems, depend on replacing indirect branches with call-return pairs. BTR circumvents this by targeting the return stack buffer prediction mechanism instead, which operates independently of Retpoline protections.

Linux kernel memory exposure poses particular risk. Attackers executing unprivileged code on a system can read kernel structures, extract memory addresses, defeat Address Space Layout Randomization (ASLR), and potentially escalate privileges. In multi-tenant cloud environments, this enables container escape and data exfiltration from neighboring workloads. Browser-based attacks allow JavaScript executed from compromised websites to leak secrets from other browser tabs, including authentication tokens and sensitive user data.

The affected ecosystem spans nearly all modern processors. Intel, AMD, and ARM CPUs using speculative execution remain vulnerable. The attack succeeds against current Linux kernel versions even with existing mitigations enabled. Windows and macOS systems may face similar exposure depending on their branch prediction implementations.

Exploitation requires only unprivileged code execution or JavaScript access. No special privileges or kernel modifications are necessary. The attack combines relative ease of delivery with high reliability, making it a credible threat for real-world exploitation.

VUSec and Sant'Anna disclosed findings responsibly to CPU vendors and Linux maintainers before public release. Current recommendations center on disabling JIT compilation where possible, though this significantly impacts performance. Kernel-level workarounds remain limited. Hardware fixes require microcode updates or microarchitectural changes that vendors will roll out incrementally.

Organizations should treat BTR as an active threat requiring layered defenses. Reducing JIT access for untrusted code, implementing strict Content Security Policies in browsers, and limiting unprivileged user access on shared systems all reduce attack surface. Cloud providers should isolate tenant workloads more aggressively until microcode patches arrive. Security teams need to monitor for memory-disclosure exploits targeting systems pending fixes.

BTR demonstrates that Spectre remains relevant years after initial disclosure. Defending against transient execution attacks requires continued vigilance and architectural changes that vendors implement slowly. Full mitigation likely spans multiple years of hardware and software updates.