Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Spectre v2 Variant Puts Intel, AMD, Arm CPUs at Risk

Spectre v2 Variant Puts Intel, AMD, Arm CPUs at Risk

Posted on September 29, 2026 By CWS

A recently discovered variant of the Spectre v2 vulnerability has been found to threaten Intel, AMD, and Arm processors. This new risk, dubbed Branch Target Reuse (BTR), was uncovered by researchers from Vrije Universiteit Amsterdam and Scuola Superiore Sant’Anna. The vulnerability exploits just-in-time (JIT) compilers used by operating system kernels, web browsers, and various runtimes.

Branch Target Reuse: A Deeper Dive

BTR allows attackers with code execution capabilities on a machine to potentially extract sensitive data from memory, including password hashes. The attack is particularly potent when launched from malicious web pages, although a full browser exploit has yet to be developed. The root of the vulnerability lies in how processors handle code changes during runtime. Specifically, while modern CPUs maintain code coherence, they may not refresh indirect branch prediction entries.

This oversight creates a scenario where stale predictions can be exploited in JIT engines, allowing an attacker to hijack speculative execution into new code at old offsets. This technique, known as speculative execute-after-free, has been demonstrated against various environments, including the Linux kernel.

Exploiting the Linux Kernel and Browsers

In their experiments, the researchers crafted exploits targeting the Linux kernel, specifically leveraging classic BPF (cBPF). While eBPF JIT is restricted to privileged users, cBPF remains accessible to unprivileged programs and is widely used in applications like Docker and Chrome for filtering tasks. The exploit effectively bypasses existing mitigations on modern Intel CPUs, leaking sensitive information even from fully updated systems.

Browser environments are also vulnerable. In Firefox, a malicious site could execute JavaScript code to exploit shared address spaces, potentially leaking data at considerable rates. The researchers’ proof-of-concept showed that in Firefox’s SpiderMonkey engine, stale branch entries could be reused long enough to leak data. However, a complete browser exploit remains undeveloped.

Mitigation and Industry Response

The vulnerability has been reported to affected hardware and software vendors, who recognize the need for software-based mitigations. Existing mechanisms like the indirect branch prediction barrier (IBPB) can reduce BTR risks, and Linux developers have introduced an x86 mitigation that applies an IBPB when reusing memory regions for cBPF programs.

Despite these efforts, complete protection requires hardware-level updates. Current CPUs lack a mechanism to keep branch predictors aligned with memory code, leaving systems vulnerable until such features are implemented. Some mitigations, like IBT and BTI, complicate exploitation but do not wholly eliminate it. Notably, only Intel’s Lion Cove generation is free from the observed race condition.

SecurityWeek reached out to Intel, AMD, and Arm for comments. While AMD claims the research does not expose new vulnerabilities in its products, Intel and Arm have yet to respond. As industry efforts continue to address this issue, users are advised to stay vigilant and apply available software updates.

Security Week News Tags:AMD, Arm, branch prediction, browser vulnerabilities, BTR attack, CPU security, Cybersecurity, Exploit, hardware security, Intel, JIT compilers, Linux kernel, Spectre v2

Post navigation

Previous Post: New BTR Attack Compromises Linux Despite Defenses
Next Post: Silver Fox Hackers Exploit Fake Software Sites for Malware

Related Posts

PLoB: A Behavioral Fingerprinting Framework to Hunt for Malicious Logins PLoB: A Behavioral Fingerprinting Framework to Hunt for Malicious Logins Security Week News
Why Scamming Can’t Be Stopped—But It Can Be Managed Why Scamming Can’t Be Stopped—But It Can Be Managed Security Week News
Google API Keys in Android Apps Risk Data Breach Google API Keys in Android Apps Risk Data Breach Security Week News
Bell Ambulance Data Breach Affects 238,000 Individuals Bell Ambulance Data Breach Affects 238,000 Individuals Security Week News
Microsoft Patches Office Zero-Day Likely Exploited in Targeted Attacks Microsoft Patches Office Zero-Day Likely Exploited in Targeted Attacks Security Week News
Mini Shai-Hulud Attack Targets 320+ NPM Packages Mini Shai-Hulud Attack Targets 320+ NPM Packages Security Week News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Silver Fox Hackers Exploit Fake Software Sites for Malware
  • Spectre v2 Variant Puts Intel, AMD, Arm CPUs at Risk
  • New BTR Attack Compromises Linux Despite Defenses
  • Ethereum Used for Covert Malware Communication
  • Pentagon Data Breach Affects Over 3 Million Individuals

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Silver Fox Hackers Exploit Fake Software Sites for Malware
  • Spectre v2 Variant Puts Intel, AMD, Arm CPUs at Risk
  • New BTR Attack Compromises Linux Despite Defenses
  • Ethereum Used for Covert Malware Communication
  • Pentagon Data Breach Affects Over 3 Million Individuals

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark