Skip to main content
Mallory
Back to intelligence
patch-regressionwidely-deployed-product-advisoryendpoint-software-vulnerability

AMD Firmware Update Removes Memory Encryption From Consumer Ryzen CPUs

Updated 1d agoFirst seen Jun 15, 20262 sources

AMD appears to have disabled Transparent Secure Memory Encryption (TSME) on non-Pro Ryzen processors through newer AGESA 1.2.7.0 firmware, leaving the feature reported as unsupported on consumer systems that previously exposed it. Security researcher Ben Kilpatrick traced the change after noticing TSME had disappeared on his Ryzen system, and testing by MSI engineers found the same pattern on MSI and Gigabyte motherboards: older AGESA firmware showed TSME enabled on consumer Ryzen chips, while newer firmware did not. Ryzen Pro processors continued to report TSME support across both motherboard vendors and firmware versions.

AMD has not publicly clarified whether the change was an intentional product restriction or an unintended regression. In responses on AMD’s public engineering GitHub, engineers suggested checking the BIOS setting and escalating unresolved cases to motherboard vendors, while a cited official statement said TSME is part of AMD PRO Technologies and applies only to Pro CPUs. The loss of TSME may reduce defenses against physical memory attacks, including cold-boot attacks, DRAM snooping, and memory extraction from removed modules, and users may have difficulty detecting the change, particularly on Windows systems.

Share:
AMD Firmware Update Removes Memory Encryption From Consumer Ryzen CPUs
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

4 events from the most recent confirmed update back to the earliest known activity.

4 EVENTS
Jun 17, 20261d ago

AMD statement says TSME is only part of PRO CPU security features

An AMD statement cited in reporting said TSME is a security feature applied only to PRO CPUs as part of AMD PRO Technologies. This contrasted with prior observations that consumer Ryzen chips had shown TSME support under older firmware.

AMD silently removes memory encryption from consumer Ryzen CPUs, leaving users unaware that they may be vulnerable - security feature vanishes after newer AGESA firmware, AMD engineers go radio silent when pressed about the change | Tom's Hardware
Jun 15, 20263d ago

Kilpatrick files public AMD GitHub bug report on TSME issue

Kilpatrick filed a bug report on AMD's public engineering GitHub repository about TSME no longer appearing supported on consumer Ryzen systems. AMD engineers replied by suggesting a BIOS toggle and, if that failed, escalation to the motherboard vendor, without clearly explaining the change.

Users cry foul after AMD stripped memory crypto from its consumer CPUs - Ars Technica

Researcher Ben Kilpatrick investigates missing TSME support

Ben Kilpatrick investigated why TSME was no longer reported as supported on his consumer AMD Ryzen CPU and documented the discrepancy between older and newer firmware behavior. His work helped surface the issue publicly as a possible restriction or regression affecting non-Pro Ryzen chips.

Users cry foul after AMD stripped memory crypto from its consumer CPUs - Ars Technica

New AGESA firmware stops reporting TSME on consumer Ryzen CPUs

Testing by MSI engineers found that consumer AMD Ryzen CPUs on MSI and Gigabyte motherboards showed Transparent Secure Memory Encryption enabled with older AMD AGESA firmware, but newer AGESA 1.2.7.0 reported the feature as unsupported. Ryzen Pro CPUs continued to support TSME across both motherboard vendors and firmware versions.

Users cry foul after AMD stripped memory crypto from its consumer CPUs - Ars Technica
LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

8 LINKEDOpen in app
Affected products
2 linked
LinuxAmd Generic Encapsulated Software Architecture
Organizations
6 linked
Advanced Micro DevicesMicro-Star InternationalTom's HardwareArs TechnicaGitHubGIGABYTE Technology
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.

AMD Firmware Update Removes Memory Encryption From Consumer Ryzen CPUs | Mallory