"Pixel-Stealing Attack Exposes Vulnerabilities in Major GPU Suppliers"
TL;DR Summary
GPUs from all major suppliers, including Apple, Intel, AMD, Qualcomm, Arm, and Nvidia, are vulnerable to a newly discovered cross-origin attack called GPU.zip. This attack allows malicious websites to read sensitive visual data, such as usernames and passwords, displayed by other websites. By exploiting a compression side channel in GPUs, attackers can bypass the same origin policy and steal pixels one by one. The attack works on both internal and discrete GPUs and requires the user to load the malicious page in Chrome or Edge browsers. Firefox and Safari are not vulnerable to this attack.
Topics:technology#compression-side-channel#cross-origin-attack#cybersecurity#data-privacy#gpus#same-origin-policy
Reading Insights
Total Reads
0
Unique Readers
11
Time Saved
4 min
vs 5 min read
Condensed
90%
923 → 95 words
Want the full story? Read the original article
Read on Ars Technica