Your TEE Is Only as Strong as Its Interconnect: Breaking SEV-SNP using AMD's Infinity Fabric

Chris, Benedict Schlueter

OffensiveCon 2026 · Day 2 · Main Stage

In this highly technical talk from OffensiveCon, Chris and Benedict Schlueter unveiled two novel attacks, "Fabric" and "Breakfast," that fundamentally undermine the security guarantees of AMD's **Secure Encrypted Virtualization-Secure Nested Paging (SEV-SNP)**. Their research demonstrates how vulnerabilities within the **AMD Infinity Fabric**, the critical interconnect component of Zen-based System-on-Chips (SoCs), can be exploited to bypass SEV-SNP's memory encryption and integrity protections. The presentation meticulously details how an untrusted hypervisor can manipulate low-level platform routing to gain unauthorized access to confidential guest data and even pave the way for arbitrary code execution on the Platform Security Processor (PSP), the root of trust for AMD platforms.

AI review

Chris and Benedict drop a genuinely new attack class — interconnect corruption — that breaks SEV-SNP not through the usual microcode or firmware fuzzing path but by weaponizing the Infinity Fabric's MMIO routing configuration against the PSP itself. This is original, deep, and structurally important: it invalidates a foundational assumption in AMD's confidential computing threat model, and AMD shipping firmware mitigations confirms the real-world severity.

Watch on YouTube