Security researcher Christopher Domas has unveiled a deep-seated attack targeting AMD Family 16h processors, including Jaguar and Puma APUs. Presented at Black Hat USA 2026, the "Skitter Creek Bath Salts" exploit uses modified DRAM controller address translation.
The attack targets RAM address translation rather than software flaws by toggling a bank swizzling register bit during operation. This creates memory aliases, allowing the dram_dump and dram_poke tools to read and write to protected PSP, SMM, and microcode areas.
While requiring root privileges and a custom Linux kernel module, the exploit bypasses core hardware protections. It targets volatile data without permanent microcode changes. AMD Family 17h and consoles remain unproven targets, and no CVE has been assigned.