Wednesday, November 5, 2025
  • Login
Euro Times
No Result
View All Result
  • Home
  • Finance
  • Business
  • World
  • Politics
  • Markets
  • Stock Market
  • Cryptocurrency
  • Investing
  • Health
  • Technology
  • Home
  • Finance
  • Business
  • World
  • Politics
  • Markets
  • Stock Market
  • Cryptocurrency
  • Investing
  • Health
  • Technology
Euro Times
No Result
View All Result

Hot Pixels attacks exploit power management in modern SoC and GPUs to leak data

by Euro Times
May 30, 2023
in Technology
Reading Time: 3 mins read
A A
0
Home Technology
Share on FacebookShare on Twitter


In context: Dynamic voltage and frequency scaling (DVFS) is a technique adopted by modern CPUs and graphics chips to manage power and speed, adjusting frequency and voltage “on the fly” to reduce energy consumption and heat generation. With a “Hot Pixels” attack, DVFS becomes yet another channel a (very) resourceful attacker could exploit to steal data and compromise user’s privacy.

Hot Pixels is a new side-channel attack conceived by an international team of researchersposing a theoretical security threat that exploits Dynamic Voltage and Frequency Scaling (DVFS) techniques to “probe analog properties” of computing devices. DVFS is essential in maintaining a delicate balance between power consumption, heat dissipation, and execution speed (i.e., frequency), the researchers explain in their paper. However, it also introduces software-visible hybrid side-channels through which sensitive data can be extracted.

The researchers targeted Arm-based SoC units, Intel CPUs, and discrete GPUs manufactured by AMD and Nvidia, as these are the most prevalent microchips currently available in the market. A side-channel attack is an attack that leverages residual information, which can be extracted due to the inherent operational nature of a computer component, rather than by exploiting specific security flaws in the design.

The team examined the vulnerability of the aforementioned computing devices to information leakage via power, temperature, and frequency values, which can be conveniently read on a local system thanks to the internal sensors embedded in the chips themselves. No admin access is necessary in this case: the data is persistently available, and DVFS values can be manipulated to operate as constants to assist in identifying specific instructions and operations.

In their experiments with DVFS readings, the researchers discovered that passively-cooled processors (like Arm chips used in smartphones) can leak information via power and frequency readings. Conversely, actively-cooled processors, such as desktop CPUs and GPUs, can leak information through temperature and power readings.

The “Hot Pixels” attacks were thus designed as a practical demonstration of the DVFS-related issue. This includes a JavaScript-based pixel stealing proof-of-concept technique, history-sniffing attacks, and website fingerprinting attacks. The researchers targeted the latest versions of Chrome and Safari web browsers, with all side-channel protections enabled and standard “user” access privileges.

The attacks could discern the color of the pixels displayed on the target’s screen through CPU frequency leakage. They achieve this by employing Scalable Vector Graphics (SVG) filters to induce data-dependent execution on the target CPU or GPU, then using JavaScript to measure the computation time and frequency to infer the pixel color.

The accuracy of these measurements ranges between 60% and 94%, while the time required to identify each pixel varies between 8.1 and 22.4 seconds. The AMD Radeon RX 6600 GPU appears to be the most vulnerable device to “Hot Pixels” attacks, while Apple SoCs (M1, M2) seem to be the most secure.

In Safari, which restricts cookie transmission on iframe elements that don’t share the same origin as the parent page, researchers had to employ more creative strategies. Apple’s browser is susceptible to a sub-type of the “Hot Pixels” attack, which can infringe on the user’s privacy by extracting browsing history. In this case, the SVG filtering technique is used to detect the differing color of a previously visited URL, achieving a higher level of accuracy ranging from 88.8% (MacBook Air M1) to 99.3% (iPhone 13).

The researchers have already reported the “Hot Pixels” issue to Intel, AMD, Nvidia, and other affected companies. However, an effective countermeasure against this new and complex type of side-channel attacks does not exist yet. Users need not be overly concerned for the time being, as the current speed limit for data exfiltration is a mere 0.1 bits per second, even though this could be “optimized” with further research.



Source link

Tags: attacksDataExploitGPUsHotleakManagementModernPixelsPowerSoC
Previous Post

Debt Ceiling Deal Includes New Work Requirements for Food Stamps

Next Post

Air Canada pilots end 10-year contract framework, eye bargaining By Reuters

Related Posts

Windows 11 Previews a Feature That Lets You Share Audio With Another Person’s Device

Windows 11 Previews a Feature That Lets You Share Audio With Another Person’s Device

by Joe Hindy
November 4, 2025
0

Wish to watch a film with your loved ones or associates, however nonetheless permit every individual to make use of...

T-Mobile customers are getting an unexpected alert that their DashPass perks are gone

T-Mobile customers are getting an unexpected alert that their DashPass perks are gone

by Ryan McNeal
November 4, 2025
0

Joe Maring / Android AuthorityTL;DR Some T-Cellular customers are receiving a textual content message from the service saying that their...

Nintendo is raising its Switch 2 sales expectations

Nintendo is raising its Switch 2 sales expectations

by Jess Weatherbed
November 4, 2025
0

The Swap 2’s recognition has exceeded even Nintendo’s anticipations, with the corporate elevating its gross sales forecast for the console...

Logitech is going after keyboard snobs with the hot-swappable Alto Keys K98M

Logitech is going after keyboard snobs with the hot-swappable Alto Keys K98M

by Jackson Chen
November 4, 2025
0

Logitech is hoping to draw all of the keebheads on the market with its newest Alto Keys K98M. Whereas this...

Elad Gil on which AI markets have winners — and which are still wide open

Elad Gil on which AI markets have winners — and which are still wide open

by Julie Bort
November 3, 2025
0

Solo VC investor extraordinaire Elad Gil stated on stage at TechCrunch Disrupt that AI has been one of many least...

Indian digital payments company Pine Labs prices its IPO at  to .5/share, valuing it at .9B at the top end of the range, down from a B valuation in 2022 (Jagmeet Singh/TechCrunch)

Indian digital payments company Pine Labs prices its IPO at $2 to $2.5/share, valuing it at $2.9B at the top end of the range, down from a $5B valuation in 2022 (Jagmeet Singh/TechCrunch)

by Euro Times
November 3, 2025
0

Featured Podcasts Decoder with Nilay Patel: Lyft CEO David Risher on paying drivers extra and the shift to robotaxis A...

Next Post
Air Canada pilots end 10-year contract framework, eye bargaining By Reuters

Air Canada pilots end 10-year contract framework, eye bargaining By Reuters

Brazil President Proposes Ditching US Dollar For Trading Currency

Brazil President Proposes Ditching US Dollar For Trading Currency

Windows 11 Previews a Feature That Lets You Share Audio With Another Person’s Device

Windows 11 Previews a Feature That Lets You Share Audio With Another Person’s Device

November 4, 2025
Russia’s G20 summit delegation revealed — RT World News

Russia’s G20 summit delegation revealed — RT World News

November 4, 2025
High Dividend 50: Hess Midstream LP

High Dividend 50: Hess Midstream LP

November 4, 2025
Russia Celebrates National Unity Day

Russia Celebrates National Unity Day

November 5, 2025
Nemocare’s Manoj Sankar Empowers Changemakers at Adani Green Talks

Nemocare’s Manoj Sankar Empowers Changemakers at Adani Green Talks

November 4, 2025
‘Growing anti-Hindu sentiment’: Indian-origin Congressman slams JD Vance over remarks about wife Usha’s faith

‘Growing anti-Hindu sentiment’: Indian-origin Congressman slams JD Vance over remarks about wife Usha’s faith

November 4, 2025
Euro Times

Get the latest news and follow the coverage of Business & Financial News, Stock Market Updates, Analysis, and more from the trusted sources.

CATEGORIES

  • Business
  • Cryptocurrency
  • Finance
  • Health
  • Investing
  • Markets
  • Politics
  • Stock Market
  • Technology
  • Uncategorized
  • World

LATEST UPDATES

Windows 11 Previews a Feature That Lets You Share Audio With Another Person’s Device

Russia’s G20 summit delegation revealed — RT World News

  • Disclaimer
  • Privacy Policy
  • DMCA
  • Cookie Privacy Policy
  • Terms and Conditions
  • Contact us

Copyright © 2022 - Euro Times.
Euro Times is not responsible for the content of external sites.

No Result
View All Result
  • Home
  • Finance
  • Business
  • World
  • Politics
  • Markets
  • Stock Market
  • Cryptocurrency
  • Investing
  • Health
  • Technology

Copyright © 2022 - Euro Times.
Euro Times is not responsible for the content of external sites.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In