Pixel Thief: Exploiting SVG Filter Leakage in Firefox and Chrome
Sioli O'Connell, Lishay Aben Sour, Ron Magen, Daniel Genkin, Yossi Oren, Hovav Shacham, Yuval Yarom
摘要
Web privacy is challenged by pixel-stealing attacks, which allow attackers to extract content from embedded iframes and to detect visited links. To protect against multiple pixelstealing attacks that exploited timing variations in SVG filters, browser vendors repeatedly adapted their implementations to eliminate timing variations. In this work we demonstrate that past efforts are still not sufficient. We show how web-based attackers can mount cache-based side-channel attacks to monitor data-dependent memory accesses in filter rendering functions. We identify conditions under which browsers elect the non-default CPU implementation of SVG filters, and develop techniques for achieving access to the high-resolution timers required for cache attacks. We then develop efficient techniques to use the pixel-stealing attack for text recovery from embedded pages and to achieve high-speed history sniffing. To the best of our knowledge, our attack is the first to leak multiple bits per screen refresh, achieving an overall rate of 267 bits per second.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了最后一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper5
- Pixnapping: Bringing Pixel Stealing out of the Stone AgeAlan Wang, Pranav Gopalkrishnan, Yingchen Wang, Christopher W. Fletcher 等CCS 2025 · 被引用 1 次
- Power-Related Side-Channel Attacks using the Android Sensor FrameworkMathias Oberhuber, Martin Unterguggenberger, Lukas Maar, Andreas Kogler 等NDSS 2025
- Practice Makes (Im)Perfect: A Look Back at Benchmarking Practices for Microarchitectural Side-Channel AttacksIliana Fayolle, Antoine Geimer, Daniel De Almeida Braga, Clémentine MauriceCCS 2026
- Slice+Slice Baby: Generating Last-Level Cache Eviction Sets in the Blink of an EyeBradley Morgan, Gal Horowitz, Sioli O'Connell, Stephan van Schaik 等S&P 2025
- Scheduled Disclosure: Turning Power into Timing Without Frequency ScalingInwhan Chun, Isabella Siu, Riccardo PaccagnellaS&P 2025
它引用的顶会 Paper14
- Spectre Attacks: Exploiting Speculative ExecutionPaul Kocher, Jann Horn, Anders Fogh, Daniel Genkin 等S&P 2019 · 被引用 2,435 次
- ret2spec: Speculative Execution Using Return Stack BuffersGiorgi Maisuradze, Christian RossowCCS 2018 · 被引用 282 次
- ECDSA Key Extraction from Mobile Devices via Nonintrusive Physical Side ChannelsDaniel Genkin, Lev Pachmanov, Itamar Pipman, Eran Tromer 等CCS 2016 · 被引用 196 次
- Robust Website Fingerprinting Through the Cache Occupancy ChannelAnatoly Shusterman, Lachlan Kang, Yarden Haskal, Yosef Meltser 等USENIX Security 2019 · 被引用 159 次
- Theory and Practice of Finding Eviction SetsPepe Vila, Boris Köpf, José F. MoralesS&P 2019 · 被引用 145 次
相关 Paper
- Rendering Contention Channel Made Practical in Web BrowsersShujiang Wu, Jianjia Yu, Min Yang, Yinzhi CaoUSENIX Security 2022
- On the effectiveness of mitigations against floating-point timing channelsDavid Kohlbrenner, Hovav ShachamUSENIX Security 2017 · 被引用 40 次
- Awakening the Web's Sleeper Agents: Misusing Service Workers for Privacy LeakageSoroush Karami, Panagiotis Ilia, Jason PolakisNDSS 2021
- Eviction Notice: Reviving and Advancing Page Cache AttacksSudheendra Raghav Neela, Jonas Juffinger, Lukas Maar, Daniel GrussNDSS 2026 · 被引用 2 次
- TimeGaps Channels: Exploiting CPU Halted Time for Fun and ProfitYusi Feng, Xin Zhang, Sioli O'Connell, Liangwei Qiu 等ISCA 2026 · 被引用 1 次
