GPUBreach: New GPU Rowhammer Attack Enables Full System Compromise

GPUBreach: New GPU Rowhammer Attack Enables Full System Compromise

First seen 6 Apr 2026, 22:13 UTC WccftechScworldBleepingcomputerSecurityaffairs.CoGbhackers+6 85% similarity 66.9

Article Content

Browse articles
ThreatCluster

Researchers from the University of Toronto have unveiled a new attack named GPUBreach that exploits Rowhammer vulnerabilities in Nvidia's GDDR6 memory. This attack allows privilege escalation from an unprivileged CUDA kernel to root access on the host system without needing to disable the Input-Output Memory Management Unit (IOMMU). By corrupting GPU page tables, attackers can gain arbitrary read/write access to GPU memory and subsequently exploit memory-safety bugs in the Nvidia driver to achieve full system compromise. The attack can manipulate sensitive data, including cryptographic keys and machine learning model weights, significantly impacting AI workloads. The findings will be presented at the IEEE Symposium on Security & Privacy on April 13, 2026. Nvidia has acknowledged the issue and may update its security advisory, while Google awarded the researchers a $600 bug bounty for their discovery. Despite the severity, the current risk level is considered manageable by some industry players.

Key Points: • GPUBreach allows full system compromise via GPU Rowhammer attacks without disabling IOMMU. • The attack exploits memory-safety vulnerabilities in Nvidia drivers and corrupts GPU page tables. • Sensitive data, including cryptographic keys, can be manipulated or extracted through this exploit.

ThreatCluster AI

Timeline

2025-11-11
Researchers reported findings to Nvidia, Google, AWS, and Microsoft.
2026-04-06
Bleepingcomputer reports on GPUBreach attack.
2026-04-07
Heise.De and other outlets publish details on GPUBreach.
2026-04-13
Full details to be presented at IEEE Symposium on Security & Privacy.

Community

Browse all →