Researchers disclosed two GPU-based Rowhammer techniques, GDDRHammer and GeForge, that can induce bit flips in GDDR6 VRAM on certain Nvidia GPUs and break memory isolation. Tests showed the attacks against Ampere-era cards including the RTX 3060 and RTX A6000/RTX 6000, where corrupted GPU page tables or page directories allowed attackers to gain read/write access to protected VRAM regions and, in some cases, remap access into host memory. The researchers said this could escalate from GPU compromise to full control of the machine, including root-level access to system memory.
The reports said the attacks require an adversary to already run code on the target system, making shared GPU environments such as AI clusters a more plausible risk than a purely remote attack path. No in-the-wild exploitation has been reported, but the findings highlight a hardware security gap in systems where GPUs can directly access host memory. Recommended mitigations include enabling IOMMU in BIOS to restrict device DMA access to sensitive system memory and turning on ECC on supported GPUs, though both measures can impose performance or memory-capacity tradeoffs and ECC may not block every Rowhammer variant.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
The researchers said enabling IOMMU in BIOS can mitigate host-memory compromise by restricting GPU access to sensitive system memory, and enabling GPU ECC can reduce risk though with performance and memory tradeoffs. They also noted no known in-the-wild exploitation and warned that newer GPUs could potentially be susceptible even though tested impact was limited to certain Ampere-generation GDDR6 cards.
Researchers reported two new GPU-based Rowhammer attacks, GDDRHammer and GeForge, that induce bit flips in GDDR6 VRAM to corrupt GPU memory-management structures. They showed this can break VRAM isolation on affected Nvidia GPUs, including RTX 3060 and RTX 6000/A6000 models, and in some cases enable read/write access to host system memory and full machine compromise.
University of Toronto researchers disclosed GPUBreach on November 11, 2025, to NVIDIA, Google, AWS, and Microsoft. The attack uses Rowhammer-induced GDDR6 bit flips plus NVIDIA driver memory-safety bugs to achieve arbitrary GPU memory access and CPU-side privilege escalation, reportedly bypassing IOMMU protections.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
14 references tracked. Mallory keeps watching after this page renders.
schneier.com
Open sourcekaspersky.com
Open sourcecybersecuritynews.com
Open sourcesecurityaffairs.com
Open sourcegddr.fail
Open sourcegpuhammer.com
Open sourcegddr.fail
Open sourcegddr.fail
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.