Disclosing Branch Target Reuse (BTR): speculative execute-after-free in JIT engines. Code gets freed, but branch predictions survive. BTR exploits this mismatch to mount practical Spectre-v2 attacks (cBPF /etc/shadow exploit demo below). Details at: vusec.net/projects/btr
GIF

