Modern GPUs vulnerable to new side-channel attack
2023-09-27 14:06

Researchers from four American universities have developed a new GPU side-channel attack that leverages data compression to leak sensitive visual data from modern graphics cards when visiting web pages.

The researchers explain that all modern graphic processor units, especially integrated Intel and AMD chips, perform software-visible data compression even when not explicitly asked.

Specifically, they demonstrated an attack that extracts individual pixel data through a web browser on various devices and GPU architectures, as shown below.

While Hot Pixels exploits data-dependent computation times on modern processors, hinges on undocumented GPU data compression to achieve similar results.

"Most sensitive websites already deny being embedded by cross-origin websites. As a result, they are not vulnerable to the pixel stealing attack we mounted using," explains the researchers in a FAQ on the team's website.

