Spectre, the processor flaw first revealed in 2018, has a new form. Researchers from VUSec at VU Amsterdam and Scuola Superiore Sant'Anna in Italy used it to pull the root password hash out of a fully patched Linux machine with an Intel processor in about three to five minutes. They call the attack Branch Target Reuse, or BTR.

Processors guess where a program will jump next and start working ahead, which is called speculative execution. Spectre attacks trick those guesses into touching secret data. Many people assumed that code which rewrites itself was safe from one form of the attack. BTR shows it is not.

Old guesses, new code

JIT engines turn code into machine instructions while a program runs. They are inside web browsers, language runtimes and the Linux kernel. When a JIT engine frees memory and fills it with new code, the processor clears the old code but can keep its old guesses about where branches go.

An attacker can train a guess, let the code be replaced and then make the processor follow the stale guess into the new code. The researchers call this a speculative execute-after-free. It leaked data at about 8 bytes per second, enough to read a password hash.

Every chip they tried

The team confirmed the problem on Intel, AMD and Arm processors and studied the Linux kernel's classic BPF, Oracle GraalVM and SpiderMonkey, the JavaScript engine in Firefox. Full exploits were built only against the Linux kernel.

Linux has merged fixes, tracked as CVE-2026-64507 and CVE-2026-64508. Oracle now randomizes where GraalVM places its code. Mozilla is relying on site isolation in Firefox. The researchers advise installing current operating system updates.

The paper is accepted at the ACM CCS security conference.