https://seclists.org/oss-sec/2026/q3/1014: Branch Target use: Practical Spect-v2 Attacks in JIT Engines via Stale Branch Pdiction Entries
Affected Software
Frequently Asked Questions
Which analyzed targets had working end-to-end exploits?
The researchers built two end-to-end exploits against the Linux kernel. They also analyzed the attack surface of Linux cBPF, Oracle GraalVM, and SpiderMonkey, but the provided information does not state that end-to-end exploits were built for GraalVM or SpiderMonkey.
What condition enables the attack in a JIT environment?
Stale indirect-branch prediction entries must remain after the original generated code is removed or modified. When the code cache is later repopulated, obsolete branch-target offsets can be reused to redirect speculative control flow into newly generated code.
What can an attacker achieve through the stale prediction entries?
The stale entries provide a speculative execute-after-free primitive. This can let an attacker steer speculative control flow to newly generated code at obsolete offsets, potentially bypassing software hardening or reaching misaligned gadgets.