Spectre bug is back, this time to haunt JIT engines

Researchers have identified a new Spectre-style vulnerability called Branch Target Reuse that affects JIT engines in browsers and kernels. This exploit allows attackers to leak sensitive data by manipulating speculative execution in modern CPUs.
Why it matters
This vulnerability highlights ongoing security risks in speculative execution, potentially requiring new patches for major software runtimes like GraalVM and SpiderMonkey.
Researchers find a way to recover stale indirect branch prediction entries
The Spectre microarchitecture vulnerability has returned yet again, this time to vex just-in-time (JIT) engines that generate machine code for browsers, runtimes, and kernels.
The vulnerability is found in many CPUs that use speculative execution, the process of executing code before it is called to boost performance. Researchers found speculative execution opens the door to side channel attacks through which secrets can be exposed or inferred.
Get smarter about the news
Sign up free for a feed built around what you actually care about, Dive Deeper research on any story, and the full text of every article.
Create free accountAlready have an account? Sign in