Researchers Discovered Spectre v2 CPU Vulnerability

A newly identified variant dubbed Branch Target Reuse affects Intel, AMD, and Arm processors.

Updated on Sept. 29, 2026 in Cybersecurity

Isometric editorial illustration of a metallic computer processor on a dark workspace, representing a hardware security vulnerability.
Researchers have identified a new Spectre v2 variant called Branch Target Reuse, which exposes memory vulnerabilities in Intel, AMD, and Arm processors. AI Illustration. Upload story photo >

Live Poll

Do you trust that your personal devices are sufficiently protected against newly discovered hardware vulnerabilities?

Security researchers have disclosed a new Spectre v2 variant called Branch Target Reuse (BTR) that allows unauthorized access to sensitive memory. The flaw affects Intel, AMD, and Arm CPUs by misusing branch prediction mechanisms.

Why it matters

The vulnerability enables attackers to speculatively hijack execution into obsolete code, potentially exposing secrets like root password hashes. It highlights persistent security risks in how modern processors handle stale branch prediction data.

The BTR exploit leverages the failure of modern CPUs to invalidate stale indirect branch prediction entries after code self-modification. This allows for data exfiltration from kernels, web browsers, and runtimes like GraalVM and Linux cBPF.

The players

VUSec

This is a computer security research group based in the Netherlands that specializes in identifying system-level vulnerabilities.

Scuola Superiore Sant'Anna

This is a public university located in Italy that conducts advanced research in engineering and technological fields.

Intel

Intel is a leading global semiconductor manufacturer that produces CPUs used in a wide range of computing devices.

AMD

AMD is a major designer and manufacturer of processors and graphics technology for personal and enterprise computing.

Arm

Arm is a semiconductor and software design company that provides the fundamental architecture for many mobile and low-power processors.

The details

Researchers developed two end-to-end exploits capable of leaking memory contents by hijacking execution at obsolete offsets. Impacted software providers and chipmakers were notified to begin developing necessary security mitigations.

Timeline

  1. September 29, 2026: Discovery of the BTR vulnerability disclosed.

The Tech Race

This vulnerability underscores the ongoing challenge of securing speculative execution, a cornerstone of processor performance since the initial Spectre disclosures. It marks an evolution in the arms race between researchers identifying side-channel flaws and engineers securing silicon architecture.

Users may see updates for web browsers like Firefox and operating system kernels as developers implement necessary mitigations. These updates are essential to protect system memory and password hashes from potential speculative execution exploits.

The takeaway

Maintaining updated software across all kernels and runtimes is the primary defense against these hardware-based side-channel attacks. Users should ensure they install security patches as they become available to mitigate risk from potential BTR exploits.

Further reading

For more on evolving digital threats, visit the Cybersecurity section.

Source note: This article includes information reported by SecurityWeek.

Live Poll

Do you trust that your personal devices are sufficiently protected against newly discovered hardware vulnerabilities?