CVE-2023-44216
PVRIC (PowerVR Image Compression) on Imagination 2018 and later GPU devices offers software-transparent compression that enables cross-origin pixel-stealing attacks against feTurbulence and feBlend in the SVG Filter specification, aka a GPU.zip issue. For example, attackers can sometimes accurately determine text contained on a web page from one origin if they control a resource from a different origin.
Published:Sep 26, 2023
Last Modified:Nov 21, 2024
EPS:Sep 26, 2023
EPSS Score:0.00413
CVSS Score:5.3
Affected Products
Vendor
Product
Action
Vendor
Amd
Product
Ryzen 5 7600x
Amd
Ryzen 5 7600x
Vendor
Amd
Product
Ryzen 7 4800u
Amd
Ryzen 7 4800u
Vendor
Apple
Product
M1 Mac Mini
Apple
M1 Mac Mini
Vendor
Apple
Product
Macos
Apple
Macos
Vendor
Canonical
Product
Ubuntu Linux
Canonical
Ubuntu Linux
Vendor
Google
Product
Android
Google
Android
Vendor
Google
Product
Pixel 6
Google
Pixel 6
Vendor
Imaginationtech
Product
Powervr-gpu
Imaginationtech
Powervr-gpu
Vendor
Intel
Product
Core I7-10510u
Intel
Core I7-10510u
Vendor
Intel
Product
Core I7-10610u
Intel
Core I7-10610u
Vendor
Intel
Product
Core I7-11800h
Intel
Core I7-11800h
Vendor
Intel
Product
Core I7-12700k
Intel
Core I7-12700k
Vendor
Intel
Product
Core I7-8700
Intel
Core I7-8700
Vendor
Microsoft
Product
Windows 10
Microsoft
Windows 10
Vendor
Microsoft
Product
Windows 11
Microsoft
Windows 11
Vendor
Nvidia
Product
Geforce Rtx 2080 Super
Nvidia
Geforce Rtx 2080 Super
Vendor
Nvidia
Product
Geforce Rtx 3060
Nvidia
Geforce Rtx 3060
Exploits
Common Weakness Enumeration
Common Attack Pattern Enumeration and Classification (CAPEC)
Related CVEs
References
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
