bleeping-computer · Crawled Aug 7, 2026

New TONTOU CPU attack bypasses Spectre v2 fixes, leaks Linux password hashes

Read original article ↗

AI Summary

Researchers Daniël Trujillo and Mengjia Yan from MIT CSAIL discovered a new CPU-side speculative execution attack named TONTOU that bypasses Spectre v2 mitigations on Intel and AMD processors. The attack exploits a timing window between branch predictor neutralization and use by injecting timer interrupts to re-poison the branch predictor, enabling unprivileged code to leak sensitive kernel memory. The researchers demonstrated the attack on an AMD Zen 2 system, successfully extracting password hashes from /etc/shadow with 91.97% accuracy at 5.47 bytes per second, requiring only user-level access.

AI-extracted · verify before operational use

No entities or IoCs were extracted from this article.