The AI boom has made GPUs one of the most critical resources in modern cloud infrastructure. From training and fine-tuning to large-scale inference, AI workloads increasingly depend on cloud-hosted GPUs, making them a foundational component of today's computing ecosystem.
While GPU security research is well established in the mobile world, where GPU driver vulnerabilities have repeatedly enabled privilege escalation, discrete GPUs powering cloud environments have received far less attention. This raises an important question: can cloud GPUs introduce security risks beyond those traditionally seen on mobile platforms?
To answer this, we analyzed the GPU driver stacks of two major GPU vendors, which together power virtually all cloud GPU deployments. Our research shows that the impact of cloud GPU vulnerabilities can be significantly more severe than mobile privilege-escalation bugs. In GPU-enabled cloud environments, host GPU devices are routinely exposed to untrusted containers running AI workloads. Because GPU drivers operate in the kernel, vulnerabilities within them can provide powerful exploitation primitives that lead directly to full container escape.
At the same time, traditional container escape surfaces continue to shrink as components such as runc and the NVIDIA Container Toolkit become increasingly hardened. GPU drivers, however, remain comparatively under-scrutinized, making them an attractive and largely unexplored attack surface in modern cloud environments.
In this talk, we will present our methodology for discovering cloud GPU vulnerabilities, demonstrate end-to-end container escapes through GPU drivers, and showcase real-world attacks against mainstream public cloud platforms. Our findings provide practical guidance for researchers pursuing container escapes in modern cloud environments and offer new perspectives for Pwn2Own, where traditional attack surfaces are becoming increasingly difficult to exploit.
Lei Lu is a security researcher. He has focuses on application and system security. He has reported many vulnerabilities to Linux, AMD, NVIDIA, Apple, Microsoft, etc. He has presented at PHDays 2025.
Ji'an Zhou focuses on web security, cloud security, AI security and kernel security. His research has benefited numerous prominent vendors including Google, Apple, and Microsoft. He has delivered talks at Black Hat Europe 2024, Zer0Con 2025, Off-by-One Con 2025, Black Hat USA 2025, DEF CON 33, Zer0Con 2026, Black Hat Asia 2026, SAFACON 2026, deepsec.cc, and DEF CON 34.