logo

AMD, Apple, Qualcomm GPUs leak AI data in LeftoverLocals attacks

ID: 41c51b44-df74-58b7-9ae5-e5de19ebf2d4

STIX ID: report--41c51b44-df74-58b7-9ae5-e5de19ebf2d4

Feed Name: Bleeping Computer

Threat Score
72/100

Date Published: 2024-01-17

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

LeftoverLocals (CVE-2023-4969) is a GPU local-memory isolation flaw discovered by Trail of Bits that allows a malicious GPU kernel to read residual local memory from other kernels—potentially exposing LLM inputs, outputs, weights and intermediate data. A public PoC shows large data recoveries (up to hundreds of MB per query in some setups); vendors have issued partial fixes but several GPU models remain vulnerable. Recommended mitigations include automatic local-memory clearing between kernel calls, avoiding multi-tenant GPUs for sensitive workloads, and applying vendor patches where available.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.