Close Menu
  • Home
  • News
  • Cyber Security
  • Internet of Things
  • Tips and Advice

Subscribe to Updates

Get the latest creative news from FooBar about art, design and business.

What's Hot

Researchers Uncover Chrome Extensions Abusing Affiliate Links and Stealing ChatGPT Access

February 7, 2026

China-Linked UAT-8099 Targets IIS Servers in Asia with BadIIS SEO Malware

February 7, 2026

Badges, Bytes and Blackmail

February 7, 2026
Facebook X (Twitter) Instagram
Saturday, February 7
Facebook X (Twitter) Instagram Pinterest Vimeo
Cyberwire Daily
  • Home
  • News
  • Cyber Security
  • Internet of Things
  • Tips and Advice
Cyberwire Daily
Home»News»Phoenix RowHammer Attack Bypasses Advanced DDR5 Memory Protections in 109 Seconds
News

Phoenix RowHammer Attack Bypasses Advanced DDR5 Memory Protections in 109 Seconds

Team-CWDBy Team-CWDSeptember 24, 2025No Comments4 Mins Read
Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
Share
Facebook Twitter LinkedIn Pinterest Email


A team of academics from ETH Zürich and Google has discovered a new variant of a RowHammer attack targeting Double Data Rate 5 (DDR5) memory chips from South Korean semiconductor vendor SK Hynix.

The RowHammer attack variant, codenamed Phoenix (CVE-2025-6202, CVSS score: 7.1), is capable of bypassing sophisticated protection mechanisms put in place to resist the attack.

“We have proven that reliably triggering RowHammer bit flips on DDR5 devices from SK Hynix is possible on a larger scale,” the Computer Security Group (COMSEC) at ETH Zürich said. “We also proved that on-die ECC does not stop RowHammer, and RowHammer end-to-end attacks are still possible with DDR5.”

RowHammer refers to a hardware vulnerability where repeated access of a row of memory in a DRAM chip can trigger bit flips in adjacent rows, resulting in data corruption. This can be subsequently weaponized by bad actors to gain unauthorized access to data, escalate privileges, or even cause a denial-of-service.

Although first demonstrated in 2014, future DRAM chips are more likely to be susceptible to RowHammer attacks as DRAM manufacturers depend on density scaling to increase DRAM capacity.

In a study published by ETH Zürich researchers in 2020, it was found that “newer DRAM chips are more vulnerable to RowHammer: as device feature size reduces, the number of activations needed to induce a RowHammer bit flip also reduces.”

Further research into the subject has demonstrated that the vulnerability has several dimensions to it and that it’s sensitive to several variables, including environmental conditions (temperature and voltage), process variation, stored data patterns, memory access patterns, and memory control policies.

Some of the primary mitigations for RowHammer attacks include Error Correction Code (ECC) and Target Row Refresh (TRR). However, these countermeasures have been proven to be ineffective against more sophisticated attacks like TRRespass, SMASH, Half-Double, and Blacksmith.

The latest findings from ETH Zürich and Google show that it’s possible to bypass advanced TRR defenses on DDR5 memory, opening the door for what the researchers call the “first-ever RowHammer privilege escalation exploit on a standard, production-grade desktop system equipped with DDR5 memory.”

In other words, the end result is a privilege escalation exploit that obtains root on a DDR5 system with default settings in as little as 109 seconds. Specifically, the attack takes advantage of the fact that mitigation does not sample certain refresh intervals to flip bits on all 15 DDR5 memory chips in the test pool that were produced between 2021 and 2024.

Potential exploitation scenarios involving these bit flips allow for targeting RSA-2048 keys of a co-located virtual machine to break SSH authentication, as well as using the sudo binary to escalate local privileges to the root user.

CIS Build Kits

“As DRAM devices in the wild cannot be updated, they will remain vulnerable for many years,” the researchers said. “We recommend increasing the refresh rate to 3x, which stopped Phoenix from triggering bit flips on our test systems.”

The disclosure comes weeks after research teams from George Mason University and Georgia Institute of Technology detailed two different RowHammer attacks called OneFlip and ECC.fail, respectively.

While OneFlip revolves around triggering a single bit flip to alter Deep Neural Network (DNN) model weights and activate unintended behavior, ECC.fail is described as the first end-to-end RowHammer attack that’s effective against DDR4 server machines with ECC memory.

“Unlike their PC counterparts, servers have extra protections against memory data corruptions (e.g., RowHammer or cosmic ray bit flips), in the form of error correcting codes,” the researchers said. “These can detect bit flips in memory, and even potentially correct them. ECC.fail bypasses these protections by carefully inducing RowHammer bit flips at certain memory locations.”



Source

computer security cyber attacks cyber news cyber security news cyber security news today cyber security updates cyber updates data breach hacker news hacking news how to hack information security network security ransomware malware software vulnerability the hacker news
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Previous ArticleCell Tower Hacking Gear Seized Ahead of UN General Assembly
Next Article npm Package Uses QR Code Steganography to Steal Credentials
Team-CWD
  • Website

Related Posts

News

Researchers Uncover Chrome Extensions Abusing Affiliate Links and Stealing ChatGPT Access

February 7, 2026
News

China-Linked UAT-8099 Targets IIS Servers in Asia with BadIIS SEO Malware

February 7, 2026
News

Badges, Bytes and Blackmail

February 7, 2026
Add A Comment
Leave A Reply Cancel Reply

Latest News

North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels

November 24, 202522 Views

macOS Stealer Campaign Uses “Cracked” App Lures to Bypass Apple Securi

September 7, 202517 Views

North Korean Hackers Exploit Threat Intel Platforms For Phishing

September 7, 20256 Views

U.S. Treasury Sanctions DPRK IT-Worker Scheme, Exposing $600K Crypto Transfers and $1M+ Profits

September 5, 20256 Views

Ukrainian Ransomware Fugitive Added to Europe’s Most Wanted

September 11, 20255 Views
Stay In Touch
  • Facebook
  • YouTube
  • TikTok
  • WhatsApp
  • Twitter
  • Instagram
Most Popular

North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels

November 24, 202522 Views

macOS Stealer Campaign Uses “Cracked” App Lures to Bypass Apple Securi

September 7, 202517 Views

North Korean Hackers Exploit Threat Intel Platforms For Phishing

September 7, 20256 Views
Our Picks

How it preys on personal data – and how to stay safe

October 23, 2025

The hidden risks of browser extensions – and how to avoid them

September 13, 2025

How the always-on generation can level up their cybersecurity game

September 11, 2025

Subscribe to Updates

Get the latest news from cyberwiredaily.com

Facebook X (Twitter) Instagram Pinterest
  • Home
  • Contact
  • Privacy Policy
  • Terms of Use
  • California Consumer Privacy Act (CCPA)
© 2026 All rights reserved.

Type above and press Enter to search. Press Esc to cancel.