GPUBreach bypasses IOMMU on GDDR6-based NVIDIA GPUs

Researchers from the University of Toronto describe GPUBreach, a rowhammer attack against GDDR6-based NVIDIA GPUs that can bypass IOMMU protections. The technique enables CPU-side privilege escalation by abusing trusted GPU driver behavior on the host system.

Researchers from the University of Toronto have introduced GPUBreach, a rowhammer attack targeting GDDR6-based NVIDIA GPUs that can bypass IOMMU and enable CPU-side privilege escalation. The attack stands apart from earlier GDDRHammer and GeForge techniques, which were largely mitigated by enabling IOMMU through the BIOS to limit the memory regions a GPU can access on the host system.

In typical server, workstation, and PC configurations, IOMMU restricts the GPU’s access to the CPU’s physical addresses and blocks the direct memory access patterns used in conventional DMA-based attacks. GPUBreach operates through a different path. Rather than relying on unrestricted access to host memory, it targets memory-safe bugs in the GPU driver and corrupts them while the GPU remains confined to driver-assigned buffers.

When IOMMU limits direct memory access to permitted buffers, the exploit corrupts metadata within those buffers. This causes the driver, which has kernel privileges enabled on the CPU host, to perform out-of-band writes to the buffer, effectively bypassing the protection IOMMU is designed to provide. Because this trust model is built into the kernel by default and the GPU driver is treated as one of the operating system’s most trusted components, corrupted metadata can turn the driver itself into the mechanism for the bypass.

The result is a more serious outcome than earlier rowhammer attacks against these GPUs. GPUBreach grants an attacker full root privilege escalation, shifting the impact from memory corruption alone to direct compromise of the host CPU side. That makes the attack notable not just for bypassing IOMMU, but for exploiting the interaction between GPU memory behavior and privileged driver logic on the host.

72

Impact Score

Google Vids opens free video generation to all Google users

Google has made Google Vids available to anyone with a Google account, adding free access to video generation with its latest models. The move expands Google’s end-to-end video workflow and increases pressure on rivals that charge for similar tools.

Court warns against chatbot legal advice in Heppner case

A federal court found that chats with a publicly available generative Artificial Intelligence tool were not protected by attorney-client privilege or the work-product doctrine. The ruling highlights litigation risks when executives or employees use chatbots for legal guidance without lawyer supervision.

Newsom orders California to weigh Artificial Intelligence harms in contract rules

Gov. Gavin Newsom has signed an executive order directing California agencies to account for potential Artificial Intelligence harms in state contracting while expanding approved use of generative tools across government. The move follows a dispute involving Anthropic and reflects a broader split between California and the Trump administration on Artificial Intelligence oversight.

Contact Us

Got questions? Use the form to contact us.

Contact Form

Clicking next sends a verification code to your email. After verifying, you can enter your message.