Security researcher Christopher Domas disclosed a hardware attack that abuses DRAM controller address-translation and scrambling logic to remap physical memory, allowing protected regions to alias into accessible addresses on older AMD processors. The technique was demonstrated against AMD Family 16h chips, where Domas reportedly extracted data from Platform Security Processor (PSP) memory, read System Management Mode contents from SMRAM, and recovered CPU state written to DRAM during C6 idle transitions, undermining isolation below the CPU core.
Reports say the weakness is tied to a "swizzle"-style memory-mapping mechanism and can also weaken protections associated with AMD memory-encryption technologies such as SME/SEV under certain conditions. The affected processor family includes chips used in PlayStation 4 and Xbox One systems, while AMD Family 17h and later Zen-based processors are described as having architectural changes that mitigate or block this attack path. Domas characterized the issue as a broader class of architectural risk because similar memory-controller mapping designs are used across multiple CPU ecosystems, and the research is being released as the open-source project skitter-creek-bath-salts ahead of a Black Hat presentation.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
At Black Hat 2026, researchers presented findings on a hardware memory-protection weakness in older AMD processors involving a swizzle-based memory-address transformation. The presentation described how the issue could undermine PSP-linked protections and AMD SME/SEV memory encryption on AMD Family 16h systems, while noting that AMD Family 17h and newer architectures introduced changes that mitigate this attack path.
AMD published a security bulletin acknowledging the Skitter Creek Bath Salts issue affecting older Family 15h and 16h processors. AMD said the impacted chips are out of security support and that exploitation requires an attacker who already has kernel-level code execution on the machine.
Christopher Domas disclosed research on a DRAM-controller address-translation attack that can bypass hardware-enforced memory isolation by remapping physical addresses to protected DRAM cells. He released the work as the open-source project skitter-creek-bath-salts and demonstrated it on AMD Family 16h processors, including reads from PSP memory, SMRAM, and CPU state saved during C6 idle transitions.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
6 references tracked. Mallory keeps watching after this page renders.
heise.de
Open sourcetomshardware.com
Open sourceopennet.me
Open sourceopennet.ru
Open sourcecybersecuritynews.com
Open sourcegithub.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.