"Pixel-Stealing Attack Exposes Vulnerabilities in GPUs from Major Suppliers"

1 min read
Source: Slashdot
"Pixel-Stealing Attack Exposes Vulnerabilities in GPUs from Major Suppliers"
Photo: Slashdot
TL;DR Summary

Researchers have discovered a new cross-origin attack that affects GPUs from all major suppliers, allowing malicious websites to read sensitive visual data displayed by other websites. The attack violates the same origin policy, a critical security principle that isolates content hosted on different website domains. The attack, known as GPU.zip, currently only works on Chrome and Edge browsers and requires specific browser settings to be enabled. While the impact of this attack is currently limited, web developers can mitigate the threat by properly restricting sensitive pages from being embedded by cross-origin websites.

Share this article

Reading Insights

Total Reads

0

Unique Readers

11

Time Saved

2 min

vs 3 min read

Condensed

78%

41692 words

Want the full story? Read the original article

Read on Slashdot