PT-2023-29149 · Imagination Technologies · Imagination Gpu

CVE-2023-44216

·

Publicado

2023-09-26

·

Atualizado

2023-10-05

CVSS v3.1

5.3

Média

VetorAV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Imagination GPU devices versions 2018 and later
Description The issue allows for cross-origin pixel-stealing attacks against certain functions in the SVG Filter specification, such as feTurbulence and feBlend. This can enable attackers to determine text contained on a web page from one origin if they control a resource from a different origin.
Recommendations For Imagination GPU devices versions 2018 and later, consider disabling the PVRIC (PowerVR Image Compression) feature as a temporary workaround until a patch is available. Restrict access to sensitive resources to minimize the risk of exploitation. Avoid using the feTurbulence and feBlend functions in the SVG Filter specification until the issue is resolved.

Exploit

Correção

Side Channel Attack

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2023-44216

Produtos afetados

Imagination Gpu