Nvidia’s GDDR6 GPUs can be weaponised to take over the whole machine, right down to a root shell.
According to Hacking Passion, three independent research teams dumped GPU attack work at the same time, and one chain goes further than anything we have seen so far. There is currently no fix for consumer GPUs.
Dubbed GPUBreach, the breach comes from the University of Toronto. To see what the fuss is about, you need a quick refresh on Rowhammer.
DRAM is built from rows of tiny cells packed so tight they might as well be sharing a bed. Hit the same row hard enough with repeated accesses, and the electrical noise leaks into neighbouring rows, flipping bits you should never touch.
This has been a known CPU memory headache for more than a decade, but the unanswered bit was whether GDDR6 behaves the same way and it does.
The same Toronto group published GPUHammer in July 2025, showing Rowhammer-style attacks on Nvidia GDDR6 are practical. One carefully placed bit flip could take an AI model from 80 per cent accuracy to essentially zero.
Nvidia responded with a security notice, telling users to enable System-Level ECC, which most consumer GPUs cannot do.
GPUBreach is the follow-up, and it moves from corruption to privilege escalation. The researchers reverse-engineered the Nvidia driver to map out how GPU page tables get allocated and stored inside GDDR6.
Page tables are the GPU’s address book, controlling which process can see which memory. If you can rewrite them, you can rewrite reality for anything running on that GPU.
The attack uses timing quirks in GPU memory management to spot when a fresh page table region appears. The attacker frees and refills memory in a specific order, nudging a page table next to a row that is known to flip.
One targeted Rowhammer bit flip later, an unprivileged CUDA kernel gets arbitrary read and write across the entire GPU memory space. That is nasty on its own, but it gets worse.
The classic defence here is the IOMMU, which limits which physical memory a GPU can access directly. Nvidia, AMD and Microsoft all recommend keeping it enabled.
Two of the other papers, GDDRHammer from UNC Chapel Hill and Georgia Tech, and GeForge from Purdue and Rochester, require disabling the IOMMU to reach the CPU. With the IOMMU on, they stop at the GPU.
GPUBreach does not bother trying to dodge the IOMMU. It goes through the Nvidia driver instead.
A compromised GPU uses its permitted access to write into CPU memory regions that the IOMMU allows because they belong to the Nvidia kernel driver. It is less a battering ram and more a poisoned note slipped into the right inbox.
That poisoned data is processed on the CPU, triggering out-of-bounds writes. The attacker gets an arbitrary kernel write primitive, then a root shell, with the IOMMU still enabled and no usual alarms.
Once the full chain lands, it can extract secret cryptographic keys from Nvidia’s cuPQC library while key exchanges occur in GPU memory. It can leak LLM weights from GPU DRAM, which is a tidy way to nick expensive model IP in shared environments.
It can silently wreck AI accuracy by tweaking a branch inside Nvidia’s cuBLAS library in GPU memory, taking a model from 80 per cent accuracy to zero without a crash. It can finish the job with full root access on the host.
The affected hardware picture is clearer than some of the hand-waving coverage suggests. The confirmed vulnerable cards are Nvidia GPUs using GDDR6, mainly from the Ampere generation, with the RTX 3060 and RTX A6000 shown with full exploit chains.
GDDRHammer tested 25 GDDR6 GPUs and found bit flips in the majority. GDDR6X cards, such as the RTX 3080, showed no bit flips during that testing.
GDDR7 cards, including the RTX 5090, use always-on on-die ECC that is not configurable by the user, and current techniques have not found them vulnerable. For consumer desktop and laptop GPUs running GDDR6, the researchers say there are no known mitigations.
ECC is not available on gaming GPUs, so the only real protection is a driver patch fixing the memory-safety bugs GPUBreach uses. That patch does not exist yet.
The Toronto team reported GPUBreach to Nvidia, Google, AWS and Microsoft on 11 November 2025. Google acknowledged the report and paid a $600 bug bounty, which is about the price of a broken office chair.
For context, Google pays up to $250,000 for a critical Chrome sandbox escape. For an attack that can root AI infrastructure, steal post-quantum keys, and extract model weights from shared hardware, it paid $600.
Nvidia is worth close to a trillion dollars and Google is worth more than two trillion dollars, yet the researchers walked away with $600. Bug bounties are meant to encourage this work, not make it look like a joke.
Nvidia has not assigned a CVE and it has not issued a new advisory specific to GPUBreach. It pointed to its Rowhammer notice from July 2025 and said it may update it.







