Researchers disclose Spectre v2 variant 'BTR' that steals Linux root password hashes
Security researchers at VUsec and Scuola Superiore Sant'Anna developed a new Spectre v2 attack called Branch Target Reuse (BTR), which exploits stale branch predictor data left behind when JIT engines reuse memory addresses for new code. Tested against Firefox's SpiderMonkey, GraalVM, and the Linux kernel's cBPF, the attack can extract a system's root password hash within minutes on Intel processors. The flaws were assigned CVE-2026-64507 and CVE-2026-64508, and fixes have already been merged into the Linux kernel.