Vulnerabilities · 161 days ago
GPUBreach reveals that Rowhammer bit-flips in modern GDDR6 memory can corrupt GPU page tables, granting unprivileged CUDA kernels arbitrary GPU memory read/write access. This GPU-side primitive bypasses IOMMU protections, which are assumed to isolate device memory access, and can be chained with NVIDIA driver memory-safety bugs to achieve full system compromise. This breaks the common security assumption that IOMMU prevents device-originated escalation to host memory and privileges. Systems exposing GPU compute to untrusted code, such as cloud GPU instances and multi-tenant servers, face risk beyond data corruption: attackers can gain control over the entire host and all processes sharing the GPU. Although no widespread exploits are reported yet, the public release of the research and repro code raises the risk of rapid weaponization. This vulnerability demands urgent assessment in high-risk environments where untrusted CUDA execution is allowed.
4 sources covering this story
GPU Rowhammer Attack Enables Privilege Escalation
GPUBreach uses GPU Rowhammer on GDDR6 to flip bits, corrupt page tables and escalate to system root
New GPUBreach Attack Enables Full CPU Privilege Escalation via GDDR6 Bit-Flips
GPUBreach achieves full CPU privilege escalation via GDDR6 RowHammer in July 2025 research, threatening cloud AI systems.
GPUBreach: Root Shell Access Achieved via GPU Rowhammer Attack
Researchers have demonstrated that GPU Rowhammer attacks can be used to escalate privileges.
New GPUBreach attack enables system takeover via GPU rowhammer
A new attack, dubbed GPUBreach, can induce Rowhammer bit-flips on GPU GDDR6 memories to escalate privileges and lead to a full system compromise.
Part of the PlainSec briefing for 2026-04-08