Description
PVRIC (PowerVR Image Compression) on Imagination 2018 and later GPU devices offers software-transparent compression that enables cross-origin pixel-stealing attacks against feTurbulence and feBlend in the SVG Filter specification, aka a GPU.zip issue. For example, attackers can sometimes accurately determine text contained on a web page from one origin if they control a resource from a different origin.
Published: 2023-09-26
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

No vendor fix or workaround currently provided.

Additional remediation guidance may be available on OpenCVE Cloud.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2023-48575 PVRIC (PowerVR Image Compression) on Imagination 2018 and later GPU devices offers software-transparent compression that enables cross-origin pixel-stealing attacks against feTurbulence and feBlend in the SVG Filter specification, aka a GPU.zip issue. For example, attackers can sometimes accurately determine text contained on a web page from one origin if they control a resource from a different origin.
History

Tue, 24 Sep 2024 19:30:00 +0000

Type Values Removed Values Added
First Time appeared Imaginationtech
Imaginationtech powervr-gpu
CPEs cpe:2.3:h:imaginationtech:powervr-gpu:2018:*:*:*:*:*:*:*
Vendors & Products Imaginationtech
Imaginationtech powervr-gpu
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Subscriptions

Amd Ryzen 5 7600x Ryzen 7 4800u
Apple M1 Mac Mini Macos
Canonical Ubuntu Linux
Google Android Pixel 6
Imaginationtech Powervr-gpu
Intel Core I7-10510u Core I7-10610u Core I7-11800h Core I7-12700k Core I7-8700
Microsoft Windows 10 Windows 11
Nvidia Geforce Rtx 2080 Super Geforce Rtx 3060
cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-09-24T18:11:55.076Z

Reserved: 2023-09-26T00:00:00.000Z

Link: CVE-2023-44216

cve-icon Vulnrichment

Updated: 2024-08-02T19:59:51.588Z

cve-icon NVD

Status : Modified

Published: 2023-09-27T15:19:39.583

Modified: 2024-11-21T08:25:27.530

Link: CVE-2023-44216

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses