HomeSecurityHow does the new Hot Pixels attack steal data?

How does the new Hot Pixels attack steal data?

A team of researchers from Georgia Tech, the University of Michigan, and Ruhr University Bochum developed a new attack called “Hot Pixels,” which can retrieve pixels from content displayed in a target’s browser and infer browsing history.

See also: Veeam: Ransomware scams on the rise. What do they recommend?

Hot Pixels

The attack exploits data-dependent computation times in modern system-on-a-chip (SoCs) and graphics processing units (GPUs) and applies them to secretly extract information from websites you visit in Chrome and Safari.

Researchers found that modern processors struggle to balance power consumption requirements and heat dissipation constraints while achieving high execution speeds. This leads to distinct patterns of behavior that point to specific instructions and functions.

See also: Bandit Stealer: New info-stealer malware targets browsers and crypto wallets

These patterns are easily detectable through internal sensor measurements, which are often accessible through software, and depending on the device type, can help distinguish what is being viewed on the target device with up to 94% accuracy.

CPU behavior mapping on modern devices

By analyzing frequency, power, and temperature measurements in modern devices, the researchers concluded that passively cooled processors can leak information through power and frequency measurements, while those that are actively cooled can leak data through temperature and power measurements.

The researchers experimented with Apple's M1 chip, Arm's Cortex-X1 cores inside a Google Pixel 6 Pro, and Qualcomm's Snapdragon 8 Gen 1 in the OnePlus 10 Pro. They mapped the throttling points (thermal limits) and correlated the workloads with discrete frequency and power consumption measurements.

The team then experimented with data-dependent leak channels on discrete and integrated GPUs, including the Apple M1 and M2, AMD Radeon RX 6600, NVIDIA GeForce RTX 3060, and Intel Iris Xe.

The researchers conducted detailed research and characterization of how different processing behaviors, such as bit-swapping operations, could affect observable factors such as power consumption, temperature, and frequency, and used this data as a basis for evaluating the “Hot Pixels” attack.

How does the new Hot Pixels attack steal data?

How the “Hot Pixels” attack works

The “Hot Pixels” attack was tested on Chrome 108 and Safari 16.2, the latest versions available at the time of the study, in their default configuration, including all side-channel countermeasures.

The setting limits the power and temperature of the processors so that data about the color of the pixels displayed on the target screen (white or black) is passed through the processor frequency.

The attack mechanism involves leveraging SVG filters to cause data-dependent execution on the target's CPU or GPU, and then using JavaScript to measure the computation time and frequency in order to extract the pixel color.

The researchers used an iframe element on an attacker-controlled page to steal pixels from an unlinked target website. The contents of the iframe, which likely contain sensitive information about the victim, are invisible, but can be calculated by applying an SVG filter to it and measuring rendering times.

The accuracy of the measurements ranged between 60% and 94% and the time required to decipher each pixel ranged between 8.1 and 22.4 seconds.

The "leakiest" device was the AMD Radeon RX 6600, while the best-protected devices appear to be from Apple.

How does the new Hot Pixels attack steal data?

Browsing history disclosure

Safari is not affected by the attack described in the previous section because it blocks cookie transmission to iframe elements that do not have the same origin as the parent page. Therefore, the loaded pixels in the iframe will not contain user data.

However, researchers found that Safari is vulnerable to a subtype of the Hot Pixel attack, which can compromise a user's privacy by spying on their browsing history.

The devised method involves placing links to sensitive pages on the attacker-controlled website and then using the SVG filtering technique to draw conclusions about the color.

The hyperlinks of websites visited by the target should be a different color than those they have never visited, so that the basic principles of Hot Pixels attacks can be applied to infer the target's browsing history.

Also, since the entire hyperlink will be the same color, retrieving a single pixel from each hyperlink would be enough, meaning that very large lists of hyperlinks can be parsed in a short time.

The accuracy of the data stolen in this attack reached 99.3% on the iPhone 13, with just 2.5% false negatives and a recovery rate of 183 seconds per 50 hyperlinks.

Hot Pixels

Conclusion

The researchers disclosed their findings to Apple, Nvidia, AMD, Qualcomm, Intel, and Google in March. All vendors have acknowledged the issues and are working to mitigate them.

Hot Pixels attacks only work well on devices that quickly reach a steady state of power usage, such as smartphones, although the data leakage performance is generally small.

However, affected vendors and stakeholders are already discussing solutions to the reported problems, such as restricting the use of SVG filters in iframes in the HTML standard.

There are also proposals to restrict access to sensors that give heat, power, and frequency readings to unauthorized users at the operating system level.

More details about the Hot Pixels attack can be found in the technical paper the researchers published earlier this week.

Information source: bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Teo Ehc
Teo Ehchttps://www.secnews.gr
Be the limited edition.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS