HomeSecurityHackers steal data via GPU pixel theft attack

Hackers steal data via GPU pixel theft attack

Researchers have discovered a potentially scary but difficult-to-implement attack that could allow malicious websites to retrieve and intercept sensitive data. The vulnerability affects all GPU manufacturers in devices like PCs, laptops, and phones.

See also: Starfield: Loses entire stars when running on AMD Radeon GPUs
GPU

According to a paper published by researchers from four US universities, the attack, dubbed GPU.zip, is linked to data compression in the graphics unit. This attack requires a hacker to have deep knowledge of GPU compression algorithms, which are limited in their accessibility and require reverse engineering. This is not an easy endeavor.

A malicious website can use an SVG cross-origin filter to retrieve pixels displayed on another website. The operation involves visiting a website with embedded HTML iframe. The iframe links to cross-origin web pages, allowing a hacker to extract information displayed on the screen, one pixel at a time.

However, the web browser also affects the result. According to research, Firefox and Safari do not meet the requirements for GPU.zip to work.

See also: Nvidia GPU: BIOS lock broken for the first time since 2013

pixel theft

As for the fix, it's believed that GPU manufacturers have pursued a software solution. In a statement provided to Bleeping Computer, an Intel reportedly said: "While Intel did not have access to the full research paper, we have evaluated the research findings provided and determined that the root cause is not in our GPUs but in third-party software."

There's no need to panic though. Hackers have much easier ways to steal data . Most websites that contain sensitive information don't allow cross-source integration from the start.

This attack doesn't require you to immediately unplug computer , it's just a reminder of the ever-evolving hardware security race. This is yet another example that exposes hardware vulnerabilities to side-channel attacks.

See also: Elon Musk: Bought GPUs for Twitter's AI project

There will always be new ways to scam people. Some basic security measures you can take when using the internet include using strong passwords, disabling remote connections, keeping your software and operating system up to date, and using a reliable browser. Avoid suspicious websites and don't click on links that don't look trustworthy.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr/politiki-syntaxis/
Member of the Editorial Team of SecNews. He writes about cybersecurity, online fraud, privacy and technology. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS