A team of academics from ETH Zürich and Google has discovered the new Phoenix RowHammer attack variant that targets Double Data Rate 5 (DDR5) from South Korean semiconductor manufacturer SK Hynix.
See also: Clickfix attack promises “Free WiFi” but distributes malware

The RowHammer attack variant, codenamed Phoenix (CVE-2025-6202, CVSS score: 7.1), is capable of bypassing sophisticated protection mechanisms that have been put in place to resist the attack.
RowHammer refers to a hardware vulnerability where repeated access to a row of memory in a DRAM chip can cause bit flips in adjacent rows, resulting in data corruption. This can be used by malicious actors to gain unauthorized access to data, escalate privileges, or even cause a denial of service.
Although first demonstrated in 2014, future DRAM chips are more likely to be vulnerable to Phoenix RowHammer attacks as DRAM manufacturers depend on density scaling to increase DRAM capacity.
In a study published by researchers at ETH Zürich in 2020, it was found that “newer DRAM chips are more vulnerable to RowHammer: as the size of the device features decreases, the number of activations required to cause a RowHammer bit flip also decreases.”
Further research has shown that the Phoenix RowHammer vulnerability is multi-dimensional and sensitive to various factors, including environmental conditions (temperature and voltage), process variability, stored data patterns, memory access patterns, and memory control policies.
See also: PoisonSeed group registers new domains for credential theft

Some basic mitigations for RowHammer attacks include Error Correcting Code (ECC) and Target Row Refresh (TRR). However, these countermeasures have proven ineffective against more sophisticated attacks such as TRRespass, SMASH, Half-Double , and Blacksmith.
The latest findings from ETH Zürich and Google show that it is possible to bypass advanced TRR defenses in DDR5 memory, leading to what the researchers call “the first RowHammer privilege escalation exploit on a typical, productive desktop system equipped with DDR5 memory.”
The end result is a privilege escalation exploit that takes root on a DDR5 system with default settings in just 109 seconds. The attack takes advantage of the fact that mitigation does not sample certain refresh intervals to flip bits on 15 DDR5 memory chips in the test pool produced between 2021 and 2024.
Possible exploit scenarios involving these bit flips allow targeting RSA-2048 of a co-located virtual machine to compromise SSH authentication, as well as using the sudo binary to escalate local privileges to the root.
The revelation comes weeks after research teams from George Mason University and the Georgia Institute of Technology analyzed two different RowHammer attacks called OneFlip and ECC.fail, respectively.
See also: Sidewinder APT exploits protests in Nepal to distribute malware
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

While OneFlip focuses on triggering a single bit flip to change the weights of a Deep Neural Network (DNN) model and trigger unwanted behavior, ECC.fail is described as the first comprehensive RowHammer attack that is effective against DDR4 server machines with ECC memory.
