By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
World of SoftwareWorld of SoftwareWorld of Software
  • News
  • Software
  • Mobile
  • Computing
  • Gaming
  • Videos
  • More
    • Gadget
    • Web Stories
    • Trending
    • Press Release
Search
  • Privacy
  • Terms
  • Advertise
  • Contact
Copyright © All Rights Reserved. World of Software.
Reading: Phoenix RowHammer Attack Bypasses Advanced DDR5 Memory Protections in 109 Seconds
Share
Sign In
Notification Show More
Font ResizerAa
World of SoftwareWorld of Software
Font ResizerAa
  • Software
  • Mobile
  • Computing
  • Gadget
  • Gaming
  • Videos
Search
  • News
  • Software
  • Mobile
  • Computing
  • Gaming
  • Videos
  • More
    • Gadget
    • Web Stories
    • Trending
    • Press Release
Have an existing account? Sign In
Follow US
  • Privacy
  • Terms
  • Advertise
  • Contact
Copyright © All Rights Reserved. World of Software.
World of Software > Computing > Phoenix RowHammer Attack Bypasses Advanced DDR5 Memory Protections in 109 Seconds
Computing

Phoenix RowHammer Attack Bypasses Advanced DDR5 Memory Protections in 109 Seconds

News Room
Last updated: 2025/09/16 at 3:48 AM
News Room Published 16 September 2025
Share
SHARE

Sep 16, 2025Ravie LakshmananHardware Security / Vulnerability

A team of academics from ETH Zürich and Google has discovered a new variant of a RowHammer attack targeting Double Data Rate 5 (DDR5) memory chips from South Korean semiconductor vendor SK Hynix.

The RowHammer attack variant, codenamed Phoenix (CVE-2025-6202, CVSS score: 7.1), is capable of bypassing sophisticated protection mechanisms put in place to resist the attack.

“We have proven that reliably triggering RowHammer bit flips on DDR5 devices from SK Hynix is possible on a larger scale,” ETH Zürich said. “We also proved that on-die ECC does not stop RowHammer, and RowHammer end-to-end attacks are still possible with DDR5.”

Audit and Beyond

RowHammer refers to a hardware vulnerability where repeated access of a row of memory in a DRAM chip can trigger bit flips in adjacent rows, resulting in data corruption. This can be subsequently weaponized by bad actors to gain unauthorized access to data, escalate privileges, or even cause a denial-of-service.

Although first demonstrated in 2014, future DRAM chips are more likely to be susceptible to RowHammer attacks as DRAM manufacturers depend on density scaling to increase DRAM capacity.

In a study published by ETH Zürich researchers in 2020, it was found that “newer DRAM chips are more vulnerable to RowHammer: as device feature size reduces, the number of activations needed to induce a RowHammer bit flip also reduces.”

Further research into the subject has demonstrated that the vulnerability has several dimensions to it and that it’s sensitive to several variables, including environmental conditions (temperature and voltage), process variation, stored data patterns, memory access patterns, and memory control policies.

Some of the primary mitigations for RowHammer attacks include Error Correction Code (ECC) and Target Row Refresh (TRR). However, these countermeasures have been proven to be ineffective against more sophisticated attacks like TRRespass, SMASH, Half-Double, and Blacksmith.

The latest findings from ETH Zürich and Google show that it’s possible to bypass advanced TRR defenses on DDR5 memory, opening the door for what the researchers call the “first-ever RowHammer privilege escalation exploit on a standard, production-grade desktop system equipped with DDR5 memory.”

In other words, the end result is a privilege escalation exploit that obtains root on a DDR5 system with default settings in as little as 109 seconds. Specifically, the attack takes advantage of the fact that mitigation does not sample certain refresh intervals to flip bits on all 15 DDR5 memory chips in the test pool that were produced between 2021 and 2024.

Potential exploitation scenarios involving these bit flips allow for targeting RSA-2048 keys of a co-located virtual machine to break SSH authentication, as well as using the sudo binary to escalate local privileges to the root user.

CIS Build Kits

“As DRAM devices in the wild cannot be updated, they will remain vulnerable for many years,” the researchers said. “We recommend increasing the refresh rate to 3x, which stopped Phoenix from triggering bit flips on our test systems.”

The disclosure comes weeks after research teams from George Mason University and Georgia Institute of Technology detailed two different RowHammer attacks called OneFlip and ECC.fail, respectively.

While OneFlip revolves around triggering a single bit flip to alter Deep Neural Network (DNN) model weights and activate unintended behavior, ECC.fail is described as the first end-to-end RowHammer attack that’s effective against DDR4 server machines with ECC memory.

“Unlike their PC counterparts, servers have extra protections against memory data corruptions (e.g., RowHammer or cosmic ray bit flips), in the form of error correcting codes,” the researchers said. “These can detect bit flips in memory, and even potentially correct them. ECC.fail bypasses these protections by carefully inducing RowHammer bit flips at certain memory locations.”

Sign Up For Daily Newsletter

Be keep up! Get the latest breaking news delivered straight to your inbox.
By signing up, you agree to our Terms of Use and acknowledge the data practices in our Privacy Policy. You may unsubscribe at any time.
Share This Article
Facebook Twitter Email Print
Share
What do you think?
Love0
Sad0
Happy0
Sleepy0
Angry0
Dead0
Wink0
Previous Article Space42, Viasat form joint venture to launch D2D 5G mobile satellite services | Computer Weekly
Next Article Refresh Vero Beach Medical Aesthetics Expands to Vero Beach, Marking Third Location on Florida’s East Coast
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Stay Connected

248.1k Like
69.1k Follow
134k Pin
54.3k Follow

Latest News

3 Ways To Level Up Your Desk With Your Monitor’s USB Ports – BGR
News
Free Internship Certificate Templates for Employers & HR Teams
Computing
Microsoft favors Anthropic over OpenAI for Visual Studio Code
News
3 signs it’s time for a new HDMI cable
News

You Might also Like

Computing

Free Internship Certificate Templates for Employers & HR Teams

24 Min Read
Computing

What are AI Agents and Why They Matter | HackerNoon

10 Min Read
Computing

Vibe Coding Examples: Real Projects Built with AI Tools

13 Min Read
Computing

AMD ROCm 7.0 Begins Rocking Out On GitHub

2 Min Read
//

World of Software is your one-stop website for the latest tech news and updates, follow us now to get the news that matters to you.

Quick Link

  • Privacy Policy
  • Terms of use
  • Advertise
  • Contact

Topics

  • Computing
  • Software
  • Press Release
  • Trending

Sign Up for Our Newsletter

Subscribe to our newsletter to get our newest articles instantly!

World of SoftwareWorld of Software
Follow US
Copyright © All Rights Reserved. World of Software.
Welcome Back!

Sign in to your account

Lost your password?