Researchers from VUSec, Vrije Universiteit Amsterdam, and Scuola Superiore Sant’Anna disclosed Branch Target Reuse (BTR), a new Spectre v2 variant that affects Intel, AMD, and Arm CPUs. The attack can abuse JIT compilers in kernels, browsers, and runtimes to leak sensitive memory data, including the root password hash, with mitigations left largely to software. #Spectrev2 #BranchTargetReuse #VUSec #SpiderMonkey #GraalVM #LinuxKernel
Keypoints
- BTR is a new Spectre v2 variant disclosed by VUSec researchers.
- It targets JIT compilers used by kernels, browsers, and runtimes.
- Attackers could steal sensitive memory data, including password hashes.
- The researchers demonstrated end-to-end exploits against the Linux kernel.
- Mitigations rely on software changes such as IBPB, site isolation, and kernel defenses.
Read More: https://www.securityweek.com/new-spectre-v2-variant-exposes-intel-amd-arm-cpus-to-data-leaks/