New GPUBreach Attack Enables System-Wide Compromise Up to a Root Shell
ID: 97f50eab-cd5b-5a40-a35b-400667479ed2
STIX ID: report--97f50eab-cd5b-5a40-a35b-400667479ed2
Feed Name: cybersecurityNews.com
GPUBreach is a high-impact GPU Rowhammer-derived vulnerability demonstrated by University of Toronto researchers that uses targeted bit flips in GDDR6 to corrupt GPU page tables and gain arbitrary GPU memory access; by corrupting trusted NVIDIA driver metadata it can trigger kernel memory-safety bugs to obtain a CPU root shell even with IOMMU enabled. The exploit threatens cross-process GPU data theft (including post-quantum keys and LLM weights), can silently corrupt ML workloads, was responsibly disclosed to major vendors in November 2025, and while ECC memory may mitigate single-bit flips, complex multi-bit attacks can still bypass protections.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
