Researchers have disclosed a new Spectre v2 CPU vulnerability, codenamed Branch Target Reuse (BTR), that recovers Linux root password hashes on Intel hardware. The academics behind the branch target reuse attack, from VUSec and Scuola Superiore Sant’Anna, say it works against just-in-time (JIT) engines found in web browsers, language runtimes and the operating system kernel itself, and that the underlying weakness spans multiple CPU vendors rather than being specific to one chipmaker.
How the branch target reuse attack works
BTR belongs to the Spectre v2 family, the branch-prediction class of attacks that pushed vendors toward years of microcode and compiler-level mitigations. The point of those mitigations was to stop a process from steering another process’s speculative execution through shared branch predictor state. BTR gets past them anyway, and it does so while they are switched on, which is what makes it a disclosure rather than a configuration bug. Because it targets JIT engines rather than one specific piece of software, the attack surface is anywhere a JIT compiles code at runtime: a browser tab, a scripting runtime, or the kernel’s own JIT paths.
On Intel systems, that translates into a working exploit against Linux itself. BleepingComputer reports the attack recovers a root password hash in three to five minutes on average, which is fast enough to run opportunistically rather than as a lengthy, carefully staged side channel.
The practical exposure is broader than a single password file. If both a browser’s JIT and the kernel’s own JIT surfaces are reachable through the same class of weakness, then sandboxing a browser tab is not enough on its own: the kernel is a target through the same mechanism, not a separate one. Anyone running Linux on Intel silicon is exposed regardless of which application actually gets exploited first.
Two takes on one disclosure
BleepingComputer and The Hacker News published their write-ups within ten minutes of each other. By our arithmetic, that gap is short enough to point to a coordinated release timed to the researchers’ own disclosure, rather than one outlet breaking the story ahead of the other, which is the usual pattern with academic vulnerability papers.
The two accounts also read as different stories about the same finding. BleepingComputer leads with the concrete damage: a password hash and the minutes it takes to get it. The Hacker News frames the same finding around the defenses BTR gets past despite them already being deployed. Neither framing is wrong. Read together, they say more than either alone: the attack is both fast enough to matter on a live system and effective against mitigations that were supposed to have closed off exactly this class of weakness.
That pattern is familiar. Our report on a decades-old flaw in file notification systems spanning four operating systems also traced a weakness that had been sitting in plain sight, architecturally obvious once named, until someone went looking for the specific shape it takes. BTR fits the same mould: a mitigation strategy built to block known attack shapes, defeated by a shape nobody had tested against.








