bleeping-computer · Crawled Aug 7, 2026
New TONTOU CPU attack bypasses Spectre v2 fixes, leaks Linux password hashes
Read original article ↗AI Summary
Researchers Daniël Trujillo and Mengjia Yan from MIT CSAIL discovered a new CPU-side speculative execution attack named TONTOU that bypasses Spectre v2 mitigations on Intel and AMD processors. The attack exploits a timing window between branch predictor neutralization and use by injecting timer interrupts to re-poison the branch predictor, enabling unprivileged code to leak sensitive kernel memory. The researchers demonstrated the attack on an AMD Zen 2 system, successfully extracting password hashes from /etc/shadow with 91.97% accuracy at 5.47 bytes per second, requiring only user-level access.
AI-extracted · verify before operational use
No entities or IoCs were extracted from this article.