theregister.com·4 min read·hard

Spectre bug is back, this time to haunt JIT engines

T
Thomas Claburn
Spectre bug is back, this time to haunt JIT engines
✦AI Summary

Researchers have identified a new Spectre-style vulnerability called Branch Target Reuse that affects JIT engines in browsers and kernels. This exploit allows attackers to leak sensitive data by manipulating speculative execution in modern CPUs.

Why it matters

This vulnerability highlights ongoing security risks in speculative execution, potentially requiring new patches for major software runtimes like GraalVM and SpiderMonkey.

✦Dive DeeperCreate a free account to unlock

Researchers find a way to recover stale indirect branch prediction entries

The Spectre microarchitecture vulnerability has returned yet again, this time to vex just-in-time (JIT) engines that generate machine code for browsers, runtimes, and kernels.

The vulnerability is found in many CPUs that use speculative execution, the process of executing code before it is called to boost performance. Researchers found speculative execution opens the door to side channel attacks through which secrets can be exposed or inferred.

Continue reading on Headlinne

Create a free account to read the full article.

Read full article →
technologyscience
✦

Get smarter about the news

Sign up free for a feed built around what you actually care about, Dive Deeper research on any story, and the full text of every article.

Create free account

Already have an account? Sign in