
Your GPU Can Be Rooted From Inside a CUDA Kernel. Here Is Exactly How.
An unprivileged process inside a CUDA container can gain arbitrary read/write to every byte of VRAM on a shared GPU — model theft, model poisoning, private inference data exposure. No special permissions, no kernel exploits, invisible to endpoint security. This is GPUBreach: Lateral Movement, Collection, and Impact.





