Researchers reported that Rowhammer remains a practical hardware security threat, with the newer Phoenix technique showing that DDR5 memory can still be manipulated despite built-in protections. The attack revives a flaw first highlighted by Google Project Zero, which demonstrated that repeatedly accessing DRAM rows could trigger adjacent bit flips and be weaponized for privilege escalation on x86 systems, including a Linux kernel exploit that altered page table entries and a sandbox escape from Google Native Client.
The newer findings indicate that DDR5 mitigations have not eliminated the underlying risk, extending concerns that began with widespread DDR3 exposure across tested laptop models. Earlier research had already shown Rowhammer was more than a reliability issue, and the latest reports suggest modern memory modules remain susceptible to carefully engineered disturbance attacks that can undermine isolation boundaries and system integrity, renewing pressure on hardware vendors to disclose affected products and strengthen defenses.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
5 events from the most recent confirmed update back to the earliest known activity.
New reporting in September 2025 said the Phoenix Rowhammer attack could defeat DDR5 memory protections within minutes, indicating that newer DRAM generations remained vulnerable despite added defenses. This marked a renewed escalation of the Rowhammer story into DDR5-era hardware.
Testing across 29 x86 laptop models manufactured between 2010 and 2014 found Rowhammer-induced bit flips on roughly half of the systems, all using DDR3 DRAM. Google urged hardware vendors to publicly disclose mitigation information for affected past, current, and future devices.
Google mitigated the Rowhammer-related Native Client sandbox escape in Chrome 38 and 39 by disallowing the CLFLUSH instruction. This was one of the first concrete software mitigations described for the issue.
Google Project Zero reported that Rowhammer is a serious security vulnerability, not just a hardware reliability problem, and demonstrated practical exploits on multiple x86 laptops. The exploits included gaining kernel privileges on x86-64 Linux by modifying page table entries and escaping Google Native Client's sandbox.
Prior academic work by researchers at Carnegie Mellon University and Intel identified the DRAM disturbance issue later known as Rowhammer, showing that repeated accesses to memory rows can induce bit flips in adjacent cells. This established the hardware reliability basis for later security research.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
4 references tracked. Mallory keeps watching after this page renders.
theregister.com
Open sourcetechradar.com
Open sourcezdnet.com
Open sourceweb.archive.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.