Close Menu
NCIJ Network NCIJ Network
    What's Hot

    Drones Are Already on the Front Lines of Wildfire Response. Robots and AI Could Be Next.

    September 29, 2026

    Guest opinion: Wisconsin should make an AI productivity fund apprenticeship

    September 29, 2026

    Burnham has a clear vision for Britain – but not for how it fits into a troubled world | Rafael Behr

    September 29, 2026
    Facebook X (Twitter) Instagram
    Trending
    • Drones Are Already on the Front Lines of Wildfire Response. Robots and AI Could Be Next.
    • Guest opinion: Wisconsin should make an AI productivity fund apprenticeship
    • Burnham has a clear vision for Britain – but not for how it fits into a troubled world | Rafael Behr
    • Did Japan ban Israeli tourists? Here’s the truth
    • Trump unveils new site to simplify access to government services | Politics News
    • ‘I was lured into a trap’: Evan Gershkovich on moment that led to 16 months in Russian jail
    • Will pensioners be poorer as a result of Burnham scrapping the triple lock? | State pensions
    • Supreme Court Allows Rapid Third-Country Deportations, for Now
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Tuesday, September 29
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    New Spectre v2 Variant Exposes Intel, AMD, Arm CPUs to Data Leaks

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKSeptember 29, 2026 Cybersecurity No Comments5 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Researchers from the VUSec group at Vrije Universiteit Amsterdam in the Netherlands and Scuola Superiore Sant’Anna in Italy have disclosed a new variant of the Spectre v2 attack that affects systems powered by Intel, AMD, and Arm CPUs.

    The researchers named it Branch Target Reuse (BTR), and it targets the just-in-time (JIT) compilers relied upon by operating system kernels, web browsers, and runtimes.

    An attacker able to run code on a targeted machine could exploit BTR to steal sensitive data from memory, such as password hashes. Attacks launched from malicious web pages also appear feasible, but the researchers have yet to build a complete browser exploit.

    Spectre v2 BTR exploits how processors handle code that changes at runtime. “The key insight behind the attack is that, while modern CPUs restore architectural code coherence after self-modification, they do not necessarily invalidate stale indirect branch prediction entries (i.e., branch targets),” the researchers explain.

    In JIT engines, these stale predictions can outlive the code they were created for. They can later be reused once new code is written to the same memory. This results in what the researchers call a speculative execute-after-free primitive, which lets an attacker hijack speculative execution into the new code at obsolete offsets.

    The researchers analyzed Linux cBPF, Oracle’s GraalVM runtime, and SpiderMonkey, the JavaScript and WebAssembly engine in Firefox. They developed two end-to-end exploits against the Linux kernel. 

    Advertisement. Scroll to continue reading.

    Linux kernel exploit leaks the root password hash

    The kernel exploits abuse classic BPF (cBPF). While only privileged users can access the eBPF JIT, its more capable successor, cBPF can still be used by unprivileged programs. Seccomp, socket filtering, and packet filtering in applications like Docker and Chrome continue to rely on it.

    On modern Intel CPUs, the exploit leaks arbitrary memory and bypasses all enabled mitigations. According to the researchers, their exploits can extract sensitive information even when a system is fully updated and its default security settings are in place.

    “Our exploit leaks 8 bytes per second. That may sound slow, but with careful pointer chasing we only need to leak a small amount of data to reach the secret,” the researchers note. In a demo, they used the attack to locate and leak the root password hash after it was loaded into memory.

    Browsers and sandboxed runtimes are also exposed

    In Firefox, the attack would be launched from a malicious website that runs JavaScript code in the targeted user’s browser. Because Mozilla has yet to complete the rollout of site isolation, content from other tabs may share the attacker’s address space, exposing that data.

    The researchers’ proof-of-concept showed that stale branch entries persist in SpiderMonkey on Intel processors long enough to be reused. They estimate that data could leak at a rate of dozens of bytes per second, but more work is needed to build a complete browser exploit.

    In GraalVM, BTR could allow an attacker to speculatively skip over the memory masking that protects the runtime’s strictest sandbox mode against Spectre. The researchers managed to reliably reuse memory addresses, but GraalVM’s own code compilation and garbage collection processes erased the stale branch entries before they could be exploited. According to the researchers, this limitation “does not appear fundamental.”

    Fixes are left to software

    The issue was reported to impacted chipmakers and software developers, all of which acknowledged the research. CPU vendors pointed out that existing mechanisms, such as the indirect branch prediction barrier (IBPB), can mitigate BTR, and that fixes need to be implemented in software.

    Linux kernel developers have introduced an x86 mitigation that triggers an IBPB across every CPU core whenever a cBPF program is placed in a memory region that was already used by previously executed BPF code.

    Oracle has rolled out some mitigations, and Mozilla is currently prioritizing the completion of site isolation over IBPB-based mitigations.

    The researchers confirmed the underlying behavior on every CPU they tested, from Intel, AMD, and Arm. 

    The problem stems from the fact that a CPU’s branch predictor can drift out of step with the code that is actually in memory. “No current CPU has a mechanism to keep the two in sync, so until vendors add one, your CPU is vulnerable,” they warn.

    Hardware control-flow protections such as x86’s IBT and Arm’s BTI protections make exploitation more difficult but do not fully remove the threat. Older Intel CPUs can still speculatively execute instructions before the check, and Lion Cove is the earliest Intel generation the researchers found to be free of this race condition.

    However, even on race-free CPUs, the researchers were able to bypass IBT when constant blinding was disabled, although they describe race-free IBT combined with constant blinding as a much stronger defense.

    SecurityWeek has reached out to Intel, AMD and Arm for comment. AMD said the researchers’ paper did not reveal a new vulnerability in its products, and noted that the technique it describes is mitigated by existing guidance for Spectre v2 attacks.

    Intel and ARM have not responded to the request for comment.

    Related: New ‘StackWarp’ Attack Threatens Confidential VMs on AMD Processors

    Related: New Attack Targets DDR5 Memory to Steal Keys From Intel and AMD TEEs

    AMD arm CPUs data exposes intel leaks Spectre variant
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    Former US Air Force members sent to prison over BEC attacks

    DARPA Selects Xint to Use AI in Securing Military Messaging Apps

    Automated AI agent used to breach cybersecurity nonprofit DIVD

    Catch threats before they escalate with real-time Identity Telemetry

    Hackers Use ChatGPT Custom GPTs in ClickFix Attacks

    Reco Raises $55 Million for Agentic Security

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    Drones Are Already on the Front Lines of Wildfire Response. Robots and AI Could Be Next.

    September 29, 2026

    Guest opinion: Wisconsin should make an AI productivity fund apprenticeship

    September 29, 2026

    Burnham has a clear vision for Britain – but not for how it fits into a troubled world | Rafael Behr

    September 29, 2026

    Did Japan ban Israeli tourists? Here’s the truth

    September 29, 2026
    Latest Posts

    Bitcoin collateral: MARA’s $600M Long Ridge financing

    August 7, 2026

    Truck Brake Controller’s Safety Recall Doubled as Hidden Security Fix

    August 7, 2026

    The best classic slasher movie you’ll never watch

    August 7, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    Drones Are Already on the Front Lines of Wildfire Response. Robots and AI Could Be Next.

    September 29, 2026

    Guest opinion: Wisconsin should make an AI productivity fund apprenticeship

    September 29, 2026

    Burnham has a clear vision for Britain – but not for how it fits into a troubled world | Rafael Behr

    September 29, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.