Researchers Discovered New Spectre v2 CPU Vulnerability

A newly identified Spectre variant enables unauthorized memory access across Intel, AMD, and Arm processor architectures.

Updated on Sept. 29, 2026 in Cybersecurity

Bold flat-color editorial illustration featuring a detailed silicon processor wafer with repeating circuitry patterns, evoking deep-level hardware security.
Security researchers identified a new Spectre vulnerability, Branch Target Reuse, affecting Intel, AMD, and Arm processors by exploiting stale branch prediction buffers. AI Illustration. Upload story photo >

Live Poll

Do you trust that your personal devices are sufficiently protected against newly discovered hardware vulnerabilities?

Security researchers have disclosed a variant of the Spectre v2 vulnerability, dubbed Branch Target Reuse (BTR), which affects Intel, AMD, and Arm CPUs. The flaw allows attackers to leak data from system memory, including root password hashes, by exploiting stale branch prediction entries.

Why it matters

The vulnerability persists because modern CPUs fail to invalidate indirect branch prediction data after code self-modification, creating a persistent security risk for OS kernels and web browsers. This discovery mandates new software-level mitigations for environments utilizing just-in-time compilers.

Exploits leak data at a rate of 8 bytes per second on modern Intel CPUs, while performance in Firefox reaches dozens of bytes per second. The mechanism functions by speculatively hijacking execution into code at obsolete offsets.

The players

VUSec

A research group based in the Netherlands specializing in system security and side-channel vulnerability analysis.

Scuola Superiore Sant'Anna

An Italian public university known for advanced research in computer engineering and systems architecture.

The details

The vulnerability occurs when stale branch prediction entries—buffers used by CPUs to guess the next instruction—are reused after new code is written to the same memory location. By failing to clear these buffers, the CPU allows a malicious actor to speculatively hijack execution. Researchers confirmed the flaw by developing two end-to-end exploits against the Linux kernel, specifically targeting just-in-time compilers—programs that convert code into machine language during execution—within runtimes and browsers.

Timeline

  1. September 29, 2026: Article published disclosing the new Spectre v2 variant.

The Tech Race

This discovery marks a continuation of the multi-year effort to secure speculative execution architectures following the 2018 discovery of the original Spectre and Meltdown vulnerabilities. It highlights an ongoing challenge for chipmakers to balance high-speed predictive processing with isolated memory security.

Users of Linux systems, Firefox, and GraalVM are impacted by this vulnerability, though developers have already begun deploying x86 mitigations. Affected hardware ranges across the global Intel, AMD, and Arm ecosystem, necessitating software updates as they become available.

The takeaway

The BTR vulnerability underscores that speculative execution remains an active front for security research despite years of hardware-level hardening. Watch for upcoming security patches in Linux kernel updates and browser version releases to mitigate this risk.

Further reading

For more on the current state of hardware-based exploits, visit our Cybersecurity section.

Live Poll

Do you trust that your personal devices are sufficiently protected against newly discovered hardware vulnerabilities?