logo

New GPUBreach Attack Enables System-Wide Compromise Up to a Root Shell

ID: 97f50eab-cd5b-5a40-a35b-400667479ed2

STIX ID: report--97f50eab-cd5b-5a40-a35b-400667479ed2

Feed Name: cybersecurityNews.com

Threat Score
78/100

Date Published: 2026-04-07

Date Updated: 2026-04-21

Author: Abinaya

...
...

GPUBreach is a high-impact GPU Rowhammer-derived vulnerability demonstrated by University of Toronto researchers that uses targeted bit flips in GDDR6 to corrupt GPU page tables and gain arbitrary GPU memory access; by corrupting trusted NVIDIA driver metadata it can trigger kernel memory-safety bugs to obtain a CPU root shell even with IOMMU enabled. The exploit threatens cross-process GPU data theft (including post-quantum keys and LLM weights), can silently corrupt ML workloads, was responsibly disclosed to major vendors in November 2025, and while ECC memory may mitigate single-bit flips, complex multi-bit attacks can still bypass protections.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.