← Back to context

Comment by shkkmo

7 months ago

How are you sure? This isn't abusing some poorly secured screenshot API, this is a timing attack on the GPU rendering process and impacts a wide range of GPUs.

No. This isn't Spectre/Meltdown for GPUs, it takes advantage of SurfaceFlinger giving apps information on what's drawn behind them.

  • This attack measures the time needed to draw each pixel which varies due to graphical data compression. It is based on the "GPU.zip" vulnerability which was shown to affect most modern GPUs, including from Apple.