"New GPU Side-Channel Attack Exposes Major Suppliers' Vulnerabilities"

TL;DR
Researchers have discovered a new side-channel attack called GPU.zip that exploits graphical data compression in modern GPUs, rendering them vulnerable to information leakage. The attack can be used to steal pixels from a cross-origin iframe in web browsers, bypassing critical security boundaries such as same-origin policy. Chrome and Microsoft Edge are particularly susceptible, while Firefox and Safari are not impacted. The attack can be mitigated by denying cross-origin embedding and implementing X-Frame-Options and Content Security Policy rules.
Topics:technologyvulnerability-endpoint-security#gpu#graphics-processing-units#information-leakage#side-channel-attack#vulnerability-endpoint-security#web-browser-security
- Researchers Uncover New GPU Side-Channel Vulnerability Leaking Sensitive Data The Hacker News
- GPUs from all major suppliers are vulnerable to new pixel-stealing attack Ars Technica
- Modern GPUs vulnerable to new GPU.zip side-channel attack BleepingComputer
- GPUs from Nvidia, AMD, Intel, and Others Vulnerable to Pixel-Stealing GPU-zip Attack Tom's Hardware
- New GPU Side-Channel Attack Allows Malicious Websites to Steal Data SecurityWeek
- View Full Coverage on Google News
Want the full story? Read the original reporting
Read on The Hacker News