[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"branding":3,"analytics":7,"article-one-cpu-instruction-unlocks-secret-memory-on-old-amd-chips":10,"sections":35},{"siteName":4,"siteTagline":5,"publisherName":4,"contactEmail":6},"The Revision","Tech news, decoded.","editor@therevision.news",{"gaMeasurementId":8,"adsenseClientId":9},"G-ZW2MV82GYR","ca-pub-8533917693782264",{"article":11},{"id":12,"slug":13,"title":14,"dek":15,"body_md":16,"tags_json":17,"published_at":18,"created_at":19,"updated_at":20,"status":21,"review_note":22,"review_notes":23,"image_url":22,"persona_id":22,"persona_name":22,"section":24,"tags":25,"sources":30,"feedback":34,"feedback_at":22,"cost_usd":34,"total_tokens":34},4969,"one-cpu-instruction-unlocks-secret-memory-on-old-amd-chips","One CPU Instruction Unlocks Secret Memory on Old AMD Chips","A researcher found that flipping one bit on decade-old AMD FX and PS4-era chips exposes memory meant to stay hidden from every driver on the system.","**A single CPU instruction can hand an attacker the keys to AMD's most locked-down memory - if the chip is old enough to not care.**\n\nSecurity researcher Christopher Domas, known for prior finds like Sandsifter and God Mode Unlocked, has published an exploit called Skitter Creek Bath Salts that works on AMD's 15h and 16h chip families - FX-series desktops, some Opterons, and the Jaguar and Puma based chips inside the PlayStation 4 and Xbox One, all dating to roughly 2011-2015. The bug lives in a memory-interleaving setting called BankSwizzleMode, which the OS can toggle with one XOR instruction. Flip it off, map how memory scrambles back to a flat address space, flip it back on, and you can read or write to areas that are supposed to be permanently off-limits: the Platform Security Processor running the firmware TPM, System Management Mode, and microcode patch RAM. Pulling it off requires kernel-level access to load a custom driver, so this is not a remote attack - it is a way to go from already controlling the machine to controlling it at a level nothing above the hardware can audit.\n\nThat distinction matters more than the flashy technique. Rootkits that reach PSP or SMM can survive OS reinstalls and hide from every security tool running above them, which is exactly why AMD walls that memory off in the first place. It is also a reminder that hardware isolation, treated as an unbreakable boundary by every OS and hypervisor built on top of it, is only as strong as one obscure interleaving flag nobody thought to lock down.\n\nAMD's response, per its own bulletin, amounts to a shrug: these chips left security support years ago, and exploiting the bug already requires the access level of a successful attacker. Fair enough on paper - but it also means a decade of PS4s, Xbox Ones, and FX desktops now run permanently exposed hardware with no patch coming.","[\"amd\",\"cpu-security\",\"exploit\",\"hardware\"]","2026-08-14T09:33:09.000Z","2026-08-14T23:29:56.793Z","2026-08-14T23:30:08.640Z","published",null,[],"security",[26,27,28,29],"amd","cpu-security","exploit","hardware",[31],{"name":32,"url":33},"Tom's Hardware","https:\u002F\u002Fwww.tomshardware.com\u002Ftech-industry\u002Fcyber-security\u002Fjust-one-instruction-on-amds-2015-era-cpus-gets-you-access-to-platform-security-processor-microcode-and-system-management-interface-exploit-for-15h-and-16h-chip-families-cracks-open-secret-memory-areas",0,{"sections":36},[37,42,45,50,55,59,64,69,74,79,84,89,94,99],{"name":38,"slug":39,"count":40,"latest_published_at":41},"AI","ai",3293,"2026-08-20T04:00:00.000Z",{"name":43,"slug":24,"count":44,"latest_published_at":41},"Security",435,{"name":46,"slug":47,"count":48,"latest_published_at":49},"Policy","policy",210,"2026-08-19T09:32:27.000Z",{"name":51,"slug":52,"count":53,"latest_published_at":54},"Deals","deals",179,"2026-06-29T20:02:07.000Z",{"name":56,"slug":29,"count":57,"latest_published_at":58},"Hardware",140,"2026-08-19T18:25:42.000Z",{"name":60,"slug":61,"count":62,"latest_published_at":63},"Consumer Tech","consumer-tech",95,"2026-08-18T16:05:00.000Z",{"name":65,"slug":66,"count":67,"latest_published_at":68},"Science","science",90,"2026-08-19T18:41:02.000Z",{"name":70,"slug":71,"count":72,"latest_published_at":73},"Software","software",73,"2026-08-18T07:51:50.000Z",{"name":75,"slug":76,"count":77,"latest_published_at":78},"Dev Tools","dev-tools",69,"2026-08-18T04:00:00.000Z",{"name":80,"slug":81,"count":82,"latest_published_at":83},"Startups","startups",47,"2026-08-19T19:13:46.000Z",{"name":85,"slug":86,"count":87,"latest_published_at":88},"Gaming","gaming",41,"2026-07-09T04:00:00.000Z",{"name":90,"slug":91,"count":92,"latest_published_at":93},"General","general",33,"2026-08-18T22:18:13.000Z",{"name":95,"slug":96,"count":97,"latest_published_at":98},"Reviews","reviews",20,"2026-06-24T12:00:01.000Z",{"name":100,"slug":101,"count":102,"latest_published_at":103},"How-To","how-to",6,"2026-06-16T09:00:00.000Z"]