Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Spectre v2 Variant Puts Intel, AMD, Arm CPUs at Risk

Spectre v2 Variant Puts Intel, AMD, Arm CPUs at Risk

Posted on September 29, 2026 By CWS

A recently discovered variant of the Spectre v2 vulnerability has been found to threaten Intel, AMD, and Arm processors. This new risk, dubbed Branch Target Reuse (BTR), was uncovered by researchers from Vrije Universiteit Amsterdam and Scuola Superiore Sant’Anna. The vulnerability exploits just-in-time (JIT) compilers used by operating system kernels, web browsers, and various runtimes.

Branch Target Reuse: A Deeper Dive

BTR allows attackers with code execution capabilities on a machine to potentially extract sensitive data from memory, including password hashes. The attack is particularly potent when launched from malicious web pages, although a full browser exploit has yet to be developed. The root of the vulnerability lies in how processors handle code changes during runtime. Specifically, while modern CPUs maintain code coherence, they may not refresh indirect branch prediction entries.

This oversight creates a scenario where stale predictions can be exploited in JIT engines, allowing an attacker to hijack speculative execution into new code at old offsets. This technique, known as speculative execute-after-free, has been demonstrated against various environments, including the Linux kernel.

Exploiting the Linux Kernel and Browsers

In their experiments, the researchers crafted exploits targeting the Linux kernel, specifically leveraging classic BPF (cBPF). While eBPF JIT is restricted to privileged users, cBPF remains accessible to unprivileged programs and is widely used in applications like Docker and Chrome for filtering tasks. The exploit effectively bypasses existing mitigations on modern Intel CPUs, leaking sensitive information even from fully updated systems.

Browser environments are also vulnerable. In Firefox, a malicious site could execute JavaScript code to exploit shared address spaces, potentially leaking data at considerable rates. The researchers’ proof-of-concept showed that in Firefox’s SpiderMonkey engine, stale branch entries could be reused long enough to leak data. However, a complete browser exploit remains undeveloped.

Mitigation and Industry Response

The vulnerability has been reported to affected hardware and software vendors, who recognize the need for software-based mitigations. Existing mechanisms like the indirect branch prediction barrier (IBPB) can reduce BTR risks, and Linux developers have introduced an x86 mitigation that applies an IBPB when reusing memory regions for cBPF programs.

Despite these efforts, complete protection requires hardware-level updates. Current CPUs lack a mechanism to keep branch predictors aligned with memory code, leaving systems vulnerable until such features are implemented. Some mitigations, like IBT and BTI, complicate exploitation but do not wholly eliminate it. Notably, only Intel’s Lion Cove generation is free from the observed race condition.

SecurityWeek reached out to Intel, AMD, and Arm for comments. While AMD claims the research does not expose new vulnerabilities in its products, Intel and Arm have yet to respond. As industry efforts continue to address this issue, users are advised to stay vigilant and apply available software updates.

Security Week News Tags:AMD, Arm, branch prediction, browser vulnerabilities, BTR attack, CPU security, Cybersecurity, Exploit, hardware security, Intel, JIT compilers, Linux kernel, Spectre v2

Post navigation

Previous Post: New BTR Attack Compromises Linux Despite Defenses
Next Post: Silver Fox Hackers Exploit Fake Software Sites for Malware

Related Posts

Critical Cisco Email Gateway Vulnerability Exploited Critical Cisco Email Gateway Vulnerability Exploited Security Week News
CISO Conversations: Keith McCammon, CSO and Co-founder at Red Canary CISO Conversations: Keith McCammon, CSO and Co-founder at Red Canary Security Week News
Cyber Insights 2026: Social Engineering Cyber Insights 2026: Social Engineering Security Week News
Data Breach at Madera Hospital Affects 150,000 People Data Breach at Madera Hospital Affects 150,000 People Security Week News
Ivanti Patches Two EPMM Zero-Days Exploited to Hack Customers Ivanti Patches Two EPMM Zero-Days Exploited to Hack Customers Security Week News
Fraud Prevention Company SEON Raises  Million in Series C Funding Fraud Prevention Company SEON Raises $80 Million in Series C Funding Security Week News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Alleged ShinyHunters Leader Arrested by FBI and Dutch Police
  • DARPA Enlists Xint for AI-Enhanced Military App Security
  • Malicious npm Packages Trap Developers in WhatsApp Groups
  • Silver Fox Hackers Exploit Fake Software Sites for Malware
  • Spectre v2 Variant Puts Intel, AMD, Arm CPUs at Risk

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Alleged ShinyHunters Leader Arrested by FBI and Dutch Police
  • DARPA Enlists Xint for AI-Enhanced Military App Security
  • Malicious npm Packages Trap Developers in WhatsApp Groups
  • Silver Fox Hackers Exploit Fake Software Sites for Malware
  • Spectre v2 Variant Puts Intel, AMD, Arm CPUs at Risk

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark