Researchers Uncover New GPU Attack That Leaks Visual Data
-
Researchers discovered a new GPU side-channel attack called GPU.zip that leaks visual data through compression. It was demonstrated stealing pixels and usernames.
-
The attack impacts major GPU vendors like AMD, Apple, Arm, Intel, Nvidia, and Qualcomm. No patches have been released yet.
-
GPU.zip exploits undocumented GPU compression as an optimization strategy to save memory bandwidth.
-
The attack uses SVG filters and measures render times to deduce pixel colors. It takes 30-215 minutes to extract usernames.
-
The attack currently works in Chrome by loading cross-origin iframes. Firefox and Safari are not vulnerable. Websites that block iframes cannot be attacked this way.