A new pixel-stealing take advantage of can read usernames and passwords throughout websites

A new pixel-stealing take advantage of can read usernames and passwords throughout websites

Last updated 12 month ago

Software
Security
gpu
hacking

A new pixel-stealing take advantage of can read usernames and passwords throughout websites



What simply happened? Website builders have a new cause to build defenses against move-foundation embedding, as a recently published GPU compression exploit can probably make use of pass-site iframes to scouse borrow sensitive facts. Users need to carefully remember what websites they go to whilst logged into crucial services.

Researchers currently found that pics chips from all principal providers proportion a vulnerability that would permit attackers scouse borrow usernames or passwords displayed on web sites. Graphics card manufacturers and software agencies have been aware about the issue for months but haven't determined whether or not to respond.

The exploit affects Chrome and Edge internet browsers but not Firefox or Safari. Integrated and devoted pix hardware from AMD, Intel, Nvidia, Apple, Arm, and Qualcomm are susceptible.

Researchers devised a evidence-of-idea assault, dubbed GPU.Zip, wherein a malicious internet site carries embedded iframes linking to different sites a person can also have logged into. If the latter web page lets in loading go-starting place iframes with cookies and renders SVG filters on iframes the usage of the GPU, the malicious site can thieve and decode the pixels it shows. If a user is logged into an insecure page showing their username, password, or different critical statistics, it turns into seen to attackers.

Fortunately, most websites that cope with touchy data forbid pass-beginning embedding and are as a consequence unaffected. Wikipedia is a extensive exception, so editors must take greater precautions whilst surfing other websites whilst logged in. To check a website's pass-foundation security, open the developer console, reload the page, read the primary file request below the community tab, and take a look at for terms which includes "X-Frame-Options" or "Content-Security-Policy."

The trouble originates from GPU compression, which improves performance but can leak facts. Security developers commonly have little trouble with the issue due to the fact compression is traditionally visible to software and makes use of publicly to be had algorithms.

However, the new studies demonstrates the life of software program-invisible compression schemes which are proprietary to every vendor. Since graphics chip businesses withhold records in this compression, security companies have greater difficulty running around it.

Google believes current precautions from web builders are sufficient to fight the issue and hasn't indicated plans to cope with it system-extensive. Intel and Qualcomm confirmed that they may not take action, saying third-birthday celebration software is the hassle. Nvidia, AMD, Apple, and Arm have not publicly reacted to the news. No one has confirmed active exploitation inside the wild, so the vulnerability is a low precedence for now.

Nvidia says decision upscaling like DLSS (and now not native decision) is the future

Nvidia says decision upscaling like DLSS (and now not native decision) is the future

 As technology like Nvidia's DLSS and AMD's FSR permit games to improve overall performance by producing pixels and frames with AI, a few marvel if upscaling is a crutch allowing developers to launch unoptimized titles....

Last updated 12 month ago

The IRS says Microsoft owes $29 billion in returned taxes, but Redmond disagrees

The IRS says Microsoft owes $29 billion in returned taxes, but Redmond disagrees

 The Internal Revenue Service (IRS) says Microsoft owes the U.S. Government almost $29 billion in again taxes. The declare comes after an extended-walking IRS audit into Microsoft's price range from the years 2004-2013 ...

Last updated 12 month ago

Tesla cuts EV fees following production and shipping downturn

Tesla cuts EV fees following production and shipping downturn

 Tesla has slashed charges on its Model three and Model Y electric powered cars after revealing 1/3 zone delivery numbers that failed to electrify. The starting charge for a brand new Model three has fallen to $38,990 f...

Last updated 12 month ago

The Best CPU Coolers - Late 2023 Update

The Best CPU Coolers - Late 2023 Update

How need to you maintain your CPU cool? Should you go for greater conventional air coolers the usage of a heatsink or go together with an all-in-one liquid cooler with a pump and a radiator? Radiators take longer to war...

Last updated 11 month ago

Tencent turns to antique rival ByteDance to advertise its today's recreation

Tencent turns to antique rival ByteDance to advertise its today's recreation

Strange bedfellows: Tencent and ByteDance, two of China's top virtual giants, were prison competitors for years. However, an marketing expenditure analysis indicates that the former's gaming aspirations have taken prece...

Last updated 9 month ago

Cities: Skylines 2 developer warns of potential performance problems at launch

Cities: Skylines 2 developer warns of potential performance problems at launch

 In what could both be considered fresh honesty or a real instance of just how awful things have come to be, the developer of Cities: Skylines 2 has warned in advance of subsequent week's release that the sport's overal...

Last updated 11 month ago


safirsoft.com© 2023 All rights reserved

HOME | TERMS & CONDITIONS | PRIVACY POLICY | Contact