New Spectre v2 Variant Exposes Intel, AMD, Arm CPUs to Data Leaks
BLUF
A critical new side-channel vulnerability impacts virtually all major processor architectures via software execution environments.
NEWS
Researchers identified Branch Target Reuse (BTR), a Spectre v2 variant targeting Just-In-Time compilers across web browsers, runtimes, and kernels. The flaw allows attackers to leak data from systems running on Intel, AMD, and Arm hardware without physical access.
Why I Care
This affects virtually every modern computing device, from smartphones to enterprise servers, risking exposure of encryption keys and user credentials. The ubiquity of JIT compilers makes mitigation difficult without performance penalties or architectural changes.
Next Steps
Vendors should patch JIT engines immediately; users must apply OS and browser updates as soon as they are released. System administrators should monitor for unusual memory access patterns while awaiting microcode fixes.
Source: Security Week ·