By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
Digital TrustDigital TrustDigital Trust
  • Cybersecurity
    • Incident response and recovery
    • Network security
    • Phishing attacks and social engineering
    • Malware and viruses
    • Cloud security
  • Emerging Tech
    • Quantum computing
    • Artificial intelligence and machine learning
    • Blockchain technology
    • Internet of Things (IoT)
    • Augmented and virtual reality
  • Data privacy
    • GDPR compliance
    • Data protection laws and regulations
    • Data breaches and cyber attacks
    • Privacy policies and terms of service
    • User consent and data sharing
  • Business
    • Cyber insurance
    • Cybersecurity budgeting
    • Risk management and assessment
    • Digital trust and brand reputation
    • Investment and funding in cybersecurity companies
  • Compliance
    • PCI DSS compliance
    • HIPAA compliance
    • GDPR compliance
    • CCPA compliance
    • Cybersecurity laws and regulations
  • Research Center
Reading: New GPU Attack in Browsers: A Security Wake-Up Call
Share
Notification Show More
Font ResizerAa
Digital TrustDigital Trust
Font ResizerAa
  • Cybersecurity
    • Incident response and recovery
    • Network security
    • Phishing attacks and social engineering
    • Malware and viruses
    • Cloud security
  • Emerging Tech
    • Quantum computing
    • Artificial intelligence and machine learning
    • Blockchain technology
    • Internet of Things (IoT)
    • Augmented and virtual reality
  • Data privacy
    • GDPR compliance
    • Data protection laws and regulations
    • Data breaches and cyber attacks
    • Privacy policies and terms of service
    • User consent and data sharing
  • Business
    • Cyber insurance
    • Cybersecurity budgeting
    • Risk management and assessment
    • Digital trust and brand reputation
    • Investment and funding in cybersecurity companies
  • Compliance
    • PCI DSS compliance
    • HIPAA compliance
    • GDPR compliance
    • CCPA compliance
    • Cybersecurity laws and regulations
  • Research Center
Follow US
© 2024 Digital Trust, a Talk About Tech brand. All rights Reserved.
Digital Trust > Cybersecurity > Ransomware > New GPU Attack in Browsers: A Security Wake-Up Call
RansomwareSecurity Operations (SecOps)Zero Trust Architecture

New GPU Attack in Browsers: A Security Wake-Up Call

Josh Hatton
Last updated: May 3, 2024 10:09 am
Josh Hatton 2 years ago
Share
Check Point Software
SHARE

A collaborative research effort between Austria’s Graz University of Technology and France’s University of Rennes has brought to light a new type of vulnerability affecting graphics processing units (GPUs) through web browsers. This novel attack, facilitated by the WebGPU API, underscores the evolving landscape of online threats, demonstrating how attackers could exploit browser-based GPU access with minimal user interaction.

Contents
The Rise of WebGPU ExploitsExploitation without User InteractionA Call for Greater Security MeasuresBroad Impact and Industry ResponseTowards a More Secure Future

The Rise of WebGPU Exploits

The core of this research lies in the innovative use of WebGPU, an API that lets web developers harness the power of a system’s GPU for complex tasks directly within a web browser. The researchers successfully executed an attack entirely via JavaScript, emphasizing the simplicity and remote applicability of this method. “Our work emphasizes that browser vendors need to treat access to the GPU similar to other security- and privacy-related resources,” they noted, shedding light on a previously underexplored security gap.

General model – WEBGPU API

Exploitation without User Interaction

What sets this attack apart is its ability to be carried out without explicit user consent or interaction. By merely visiting a website embedded with malicious WebGPU code, users unknowingly risk exposure to potential data breaches. The study detailed methods such as inter-keystroke timing attacks, highlighting the attack’s ability to infer sensitive information, including passwords, from unsuspecting victims.

A Call for Greater Security Measures

The findings of this study serve as a crucial reminder of the latent risks associated with granting web browsers unrestricted GPU access. Lukas Giner, a researcher involved in the study, expressed concerns over potential misuse, stating, “This can lead to stealthy attacks like ours, or potentially worse ones in the future.” This observation points to the urgent need for adopting stricter security protocols and permissions for GPU access within browsers, akin to those already in place for other sensitive resources like microphones or cameras.

Broad Impact and Industry Response

This vulnerability is not confined to a specific brand or type of GPU but spans across various models from leading manufacturers like AMD and NVIDIA. It affects browsers that support WebGPU, including widely used ones like Chrome, Chromium, Edge, and Firefox Nightly. Despite the broad implications of their findings, the researchers reported a lukewarm response from industry stakeholders, with companies showing reluctance to acknowledge the potential severity of these vulnerabilities.

Towards a More Secure Future

This groundbreaking research not only highlights a critical vulnerability but also prompts a reevaluation of current security practices surrounding GPU access in web browsers. It calls for a collective effort among browser vendors, hardware manufacturers, and the cybersecurity community to mitigate these risks and protect users from emerging threats in the digital age.

By shedding light on this new attack vector, the study advocates for a proactive approach to web security, emphasizing the importance of understanding and addressing the potential for exploitation before it can cause real-world damage.

For the latest news in cyber security, visit here.

Image SOURCE

 

You Might Also Like

Infisign Revolutionizes Cybersecurity with Passwordless IAM and Zero Trust

ENIGMA Acquires Onclave Networks, Strengthens Zero Trust Cybersecurity Platform

CSA Introduces First Zero Trust Training & Credential – Get CCZT Certified!

Oracle and Industry Leaders Unveil New Open Standard for Enhanced Network and Data Security

Rising Ransomware Threats Plague Casino Industry: FBI Alerts

Share This Article
Facebook Twitter Email Print
Previous Article Ethereum’s Quantum Defense Strategy
Next Article Airbus Deal: France to Protect Atos Cybersecurity Assets France Vows to Protect Atos Cybersecurity Assets After Airbus Deal Fails
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts

XONA Raises $18M for Zero-Trust User Access in Cybersecurity

XONA Raises $18M to Enhance Zero-Trust User Access in Industrial Cybersecurity

By Conal Cram 5 Min Read
Nostra Announces Galway Cybersecurity Hub Creating 35 Jobs

Nostra’s New Cybersecurity Hub in Galway Creates 35 Jobs

By Conal Cram 4 Min Read

Deepwatch and LaceWork Securing the Cloud

By Josh Hatton 3 Min Read
OpenText spotlights the rise of Ransomware-as-a-Service

Ransomware-as-a-Service (RaaS) Dominates 2023’s Nastiest Malware, OpenText Cybersecurity Reveals

By Conal Cram 4 Min Read

From our research center

KnowBe4 Africa (Pty) Ltd

10 Questions Every CISO Should Ask About AI-Powered Human Risk Management Tools

AI is transforming security awareness—but how much is marketing hype versus genuine value for your organisation? Human risk management (HRM) and security awareness vendors of...

Read content
about us

Our dedicated team of experts and journalists brings in-depth analysis, breaking news, and comprehensive reports from around the globe.

Useful links

  • About us
  • Contact us
  • Research Center
  • Disclaimer
  • Terms & Conditions
  • Privacy

Trending topics

  • Cybersecurity
  • Emerging technologies
  • Data privacy
  • Regulations and compliance
  • Digital trust and brand reputation

Find Us on Socials

© 2024 Digital Trust, a Talk About Tech brand. All rights Reserved.
Welcome Back!

Sign in to your account

Username or Email Address
Password

Lost your password?