https://seclists.org/oss-sec/2026/q3/1014: Branch Target use: Practical Spect-v2 Attacks in JIT Engines via Stale Branch Pdiction Entries

Published Sep 30, 2026
·
Updated

Affected Software

3 affected components
Linux Linux kernel
Oracle GraalVM
Mozilla Firefox (SpiderMonkey)

Frequently Asked Questions

1

Which analyzed targets had working end-to-end exploits?

The researchers built two end-to-end exploits against the Linux kernel. They also analyzed the attack surface of Linux cBPF, Oracle GraalVM, and SpiderMonkey, but the provided information does not state that end-to-end exploits were built for GraalVM or SpiderMonkey.

2

What condition enables the attack in a JIT environment?

Stale indirect-branch prediction entries must remain after the original generated code is removed or modified. When the code cache is later repopulated, obsolete branch-target offsets can be reused to redirect speculative control flow into newly generated code.

3

What can an attacker achieve through the stale prediction entries?

The stale entries provide a speculative execute-after-free primitive. This can let an attacker steer speculative control flow to newly generated code at obsolete offsets, potentially bypassing software hardening or reaching misaligned gadgets.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203