Description
PVRIC (PowerVR Image Compression) on Imagination 2018 and later GPU devices offers software-transparent compression that enables cross-origin pixel-stealing attacks against feTurbulence and feBlend in the SVG Filter specification, aka a GPU.zip issue. For example, attackers can sometimes accurately determine text contained on a web page from one origin if they control a resource from a different origin.
References (9)
Core 9
Core References
Press/Media Coverage, Third Party Advisory
https://arstechnica.com/security/2023/09/gpus-from-all-major-suppliers-are-vulnerable-to-new-pixel-stealing-attack/
Press/Media Coverage
https://blog.imaginationtech.com/introducing-pvric4-taking-image-compression-to-the-next-level/
Press/Media Coverage
https://blog.imaginationtech.com/reducing-bandwidth-pvric/
Issue Tracking
https://news.ycombinator.com/item?id=37663159
Press/Media Coverage
https://www.bleepingcomputer.com/news/security/modern-gpus-vulnerable-to-new-gpuzip-side-channel-attack/
Technical Description
https://www.hertzbleed.com/gpu.zip/
Scores
CVSS v3
5.3
EPSS
0.0049
EPSS Percentile
65.9%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
no
Technical Impact
partial
Details
CWE
CWE-203
Status
published
Products (16)
amd/ryzen_5_7600x
amd/ryzen_7_4800u
apple/m1_mac_mini
apple/macos
13.1
canonical/ubuntu_linux
22.04
google/android
13.0
google/pixel_6
intel/core_i7-10510u
intel/core_i7-10610u
intel/core_i7-11800h
... and 6 more
Published
Sep 27, 2023
Tracked Since
Feb 18, 2026