Business CircleBusiness Circle
  • Home
  • AI News
  • Startups
  • Markets
  • Finances
  • Technology
  • More
    • Human Resource
    • Marketing & Sales
    • SMEs
    • Lifestyle
    • Trading & Stock Market
What's Hot

How founder Ruth Kudzi created a 7-figure coaching business

October 1, 2026

How To Watch NASA’s Crew-13 Launch

October 1, 2026

Micron expects fiscal Q1 revenue of $61.5B ±$1.5B as it raises fiscal 2027 CapEx plans amid tighter 2027-2028 supply-demand (NASDAQ:MU)

October 1, 2026
Facebook Twitter Instagram
Thursday, October 1
  • Advertise with us
  • Submit Articles
  • About us
  • Contact us
Business CircleBusiness Circle
  • Home
  • AI News
  • Startups
  • Markets
  • Finances
  • Technology
  • More
    • Human Resource
    • Marketing & Sales
    • SMEs
    • Lifestyle
    • Trading & Stock Market
Subscribe
Business CircleBusiness Circle
Home » A new pixel-stealing exploit can read usernames and passwords across websites
Technology

A new pixel-stealing exploit can read usernames and passwords across websites

Business Circle TeamBy Business Circle TeamSeptember 27, 2023Updated:August 21, 2025No Comments3 Mins Read
Facebook Twitter Pinterest LinkedIn Tumblr Email
A new pixel-stealing exploit can read usernames and passwords across websites
Share
Facebook Twitter LinkedIn Pinterest Email


What simply occurred? Web site builders have a brand new purpose to construct defenses in opposition to cross-origin embedding, as a not too long ago printed GPU compression exploit can probably make the most of cross-site iframes to steal delicate data. Customers ought to fastidiously think about what websites they go to whereas logged into important providers.

Researchers not too long ago found that graphics chips from all main distributors share a vulnerability that would let attackers steal usernames or passwords displayed on web sites. Graphics card producers and software program corporations have been conscious of the difficulty for months however have not determined whether or not to reply.

The exploit impacts Chrome and Edge net browsers however not Firefox or Safari. Built-in and devoted graphics {hardware} from AMD, Intel, Nvidia, Apple, Arm, and Qualcomm are vulnerable.

Researchers devised a proof-of-concept assault, dubbed GPU.zip, whereby a malicious web site incorporates embedded iframes linking to different websites a consumer could have logged into. If the latter web page permits loading cross-origin iframes with cookies and renders SVG filters on iframes utilizing the GPU, the malicious website can steal and decode the pixels it shows. If a consumer is logged into an insecure web page displaying their username, password, or different important data, it turns into seen to attackers.

Luckily, most web sites that deal with delicate information forbid cross-origin embedding and are thus unaffected. Wikipedia is a major exception, so editors ought to take further precautions when looking different websites whereas logged in. To examine a webpage’s cross-origin safety, open the developer console, reload the web page, learn the principle doc request below the community tab, and examine for phrases akin to “X-Body-Choices” or “Content material-Safety-Coverage.”

The issue originates from GPU compression, which improves efficiency however can leak information. Safety builders often have little hassle with the difficulty as a result of compression is historically seen to software program and makes use of publicly obtainable algorithms.

Nonetheless, the brand new analysis demonstrates the existence of software-invisible compression schemes which can be proprietary to every vendor. Since graphics chip corporations withhold data on this compression, safety teams have extra problem working round it.

Google believes current precautions from net builders are ample to fight the difficulty and hasn’t indicated plans to deal with it system-wide. Intel and Qualcomm confirmed that they will not take motion, saying third-party software program is the issue. Nvidia, AMD, Apple, and Arm have not publicly reacted to the information. Nobody has confirmed energetic exploitation within the wild, so the vulnerability is a low precedence for now.



Source link

exploit passwords pixelstealing Read usernames Websites
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Business Circle Team
Business Circle Team
  • Website

Related Posts

How To Watch NASA’s Crew-13 Launch

October 1, 2026

The Pentagon taps Elon Musk and Palmer Luckey to help decide what the military should do next

October 1, 2026

Miter, which provides workforce management tools for the construction industry, raised a $40M Series B led by Battery Ventures, taking its total funding to $78M (Chris Metinko/Axios)

September 30, 2026

AI tool that copied actor’s ‘lustrous’ voice violated his rights, Tokyo court rules | AI (artificial intelligence)

September 30, 2026
LATEST UPDATES

How founder Ruth Kudzi created a 7-figure coaching business

October 1, 2026

How To Watch NASA’s Crew-13 Launch

October 1, 2026

Micron expects fiscal Q1 revenue of $61.5B ±$1.5B as it raises fiscal 2027 CapEx plans amid tighter 2027-2028 supply-demand (NASDAQ:MU)

October 1, 2026

Micron (MU) Q4 FY26 Earnings Jump on Strong Revenue Growth, Beat Estimates

October 1, 2026

The hidden cost of getting discipline wrong

October 1, 2026

OpenAI, SpaceX investor funds went to strip clubs, Bloomingdale’s, and shopping on Amazon, SEC alleges in charges against private fund advisers

October 1, 2026

Subscribe to Updates

Get the latest sports news from SportsSite about soccer, football and tennis.

Business, Finance and Market Growth News Site

Important Pages
  • Advertise with us
  • Submit Articles
  • About us
  • Contact us
Recent Posts
  • How founder Ruth Kudzi created a 7-figure coaching business
  • How To Watch NASA’s Crew-13 Launch
  • Micron expects fiscal Q1 revenue of $61.5B ±$1.5B as it raises fiscal 2027 CapEx plans amid tighter 2027-2028 supply-demand (NASDAQ:MU)
© 2026 BusinessCircle.co
  • Privacy Policy
  • Terms and Conditions
  • Cookie Privacy Policy
  • Disclaimer
  • DMCA

Type above and press Enter to search. Press Esc to cancel.