
"Pixel-Stealing Attack Exposes Vulnerabilities in GPUs from Major Suppliers"
Researchers have discovered a new cross-origin attack that affects GPUs from all major suppliers, allowing malicious websites to read sensitive visual data displayed by other websites. The attack violates the same origin policy, a critical security principle that isolates content hosted on different website domains. The attack, known as GPU.zip, currently only works on Chrome and Edge browsers and requires specific browser settings to be enabled. While the impact of this attack is currently limited, web developers can mitigate the threat by properly restricting sensitive pages from being embedded by cross-origin websites.