AntiMalwareAugust 14, 2026🇷🇺Translated from Russian

AMD Memory Controller PoC Bypasses Hardware Isolation on Family 16h Processors

Security researcher Christopher Domas has published a proof-of-concept project called skitter-creek-bath-salts that demonstrates how to bypass hardware memory isolation on AMD Family 16h processors.

The technique works by manipulating settings in the DRAM controller. While software and hardware mechanisms normally enforce access control based on physical addresses, the memory controller performs the final translation into specific DRAM coordinates: channel, rank, bank, row, and column. Domas showed that changing a single register can reconfigure this translation after higher-level protections have already been applied, creating an alternative address that points to the same DRAM cells.

To keep the system stable, the PoC disables interrupts, prepares the cache and translation tables, temporarily alters the addressing scheme, performs the read or write operation, and then restores the original configuration. Address discovery relies on linear algebra and the Z3 SMT solver to map the relationship between normal and modified memory layouts and calculate aliases for protected regions.

The researcher demonstrated potential access to the AMD Platform Security Processor, including fTPM data, protected System Management Mode areas, processor C6 states, and microcode storage. The microcode scenario could allow not only extraction of a patch copy but also its modification before kernel state is restored.

The PoC has been tested exclusively on AMD Family 16h processors. No information is currently available about similar vulnerabilities affecting newer AMD generations, Intel, ARM, or RISC-V platforms.

Related articles

Security NEXTVulnerabilities & Exploits

Critical Vulnerabilities Patched in VMware Workstation and Fusion Allowing Host Code Execution

Broadcom has disclosed two vulnerabilities in VMware Workstation and VMware Fusion rated as critical and important respectively. CVE-2026-59346 is an integer overflow flaw in the VMXNET3 virtual network adapter that can be exploited by a local administrator inside a virtual machine to execute arbitrary code on the host system, carrying a CVSS v3.1 base score of 9.3. CVE-2026-59347 is a stack-based buffer overflow in the HGFS file system that permits code execution on the host as the VMX process with a CVSS score of 8.1. Both issues were privately reported and affect users who run virtual machines with local administrative privileges. The flaws have been addressed in VMware Workstation 26H1u1 and VMware Fusion 26H1u1, and Broadcom urges immediate updates via advisory VMSA-2026-0007.

Security NEXTVulnerabilities & Exploits

Google Chrome Patches 12 Vulnerabilities Including Actively Exploited V8 Zero-Day

Google has released security updates for Chrome addressing 12 vulnerabilities across Windows, macOS, and Linux platforms. The updates include versions 152.0.7977.83 and 152.0.7977.82 for Windows and macOS, and 152.0.7977.82 for Linux. No critical-rated flaws were fixed in this batch, but ten issues carry a high severity rating. The most notable is CVE-2026-85046, a type confusion flaw in the V8 JavaScript engine that was reported on August 4 and is already being exploited in the wild. Additional high-severity fixes cover a race condition in V8 (CVE-2026-85045), a use-after-free in Compositing (CVE-2026-85048), and another type confusion issue (CVE-2026-85051). This marks the second Chrome security update in three days.

HabrVulnerabilities & Exploits

Bcrypt Password Hashing Silently Ignores Characters Beyond 72 Bytes, Breaking Verification Expectations

The bcrypt algorithm, widely used for password hashing in PHP and Python applications, processes only the first 72 bytes of any input password. Additional characters are ignored without error or warning during both hashing with password_hash and verification with password_verify. This behavior stems from the fixed 72-byte P-table size in the underlying Blowfish cipher as defined in the 1999 specification. Long passphrases, especially those using multibyte UTF-8 characters like Cyrillic or emojis, can result in completely different strings producing identical hashes. The limitation creates risks during password manager usage, system migrations, and scenarios involving shared prefixes. Modern libraries such as Python's bcrypt 4.x now explicitly reject passwords exceeding 72 bytes, while older implementations continue silent truncation. Recommended fixes include enforcing byte-length validation or pre-hashing with SHA-256 before bcrypt.

Security NEXTVulnerabilities & Exploits

CISA Adds Seven Exploited Vulnerabilities in SonicWall, JFrog and Kestra to KEV Catalog

The US Cybersecurity and Infrastructure Security Agency has added seven known exploited vulnerabilities affecting SonicWall SMA1000, JFrog Artifactory and Kestra OSS products to its KEV catalog. Five of the flaws carry a three-day remediation deadline for federal agencies. Two issues in SonicWall SMA1000 enable unauthenticated server-side request forgery and authenticated OS command execution. A critical authentication bypass in JFrog Artifactory allows remote attackers to obtain administrative privileges. Kestra OSS is affected by an OS command injection vulnerability that can lead to full system compromise. CISA urges immediate patching and incident response actions.