"Pixel-Stealing Attack Exposes Vulnerabilities in Major GPU Suppliers"

1 min read
Source: Ars Technica
"Pixel-Stealing Attack Exposes Vulnerabilities in Major GPU Suppliers"
Photo: Ars Technica
TL;DR Summary

GPUs from all major suppliers, including Apple, Intel, AMD, Qualcomm, Arm, and Nvidia, are vulnerable to a newly discovered cross-origin attack called GPU.zip. This attack allows malicious websites to read sensitive visual data, such as usernames and passwords, displayed by other websites. By exploiting a compression side channel in GPUs, attackers can bypass the same origin policy and steal pixels one by one. The attack works on both internal and discrete GPUs and requires the user to load the malicious page in Chrome or Edge browsers. Firefox and Safari are not vulnerable to this attack.

Share this article

Reading Insights

Total Reads

0

Unique Readers

11

Time Saved

4 min

vs 5 min read

Condensed

90%

92395 words

Want the full story? Read the original article

Read on Ars Technica