Skip to main content

GLitch Rowhammer DRAM Attack Variant

A new variant of the Rowhammer dynamic random-access-memory (DRAM) attack has been produced that targets WebGL-enabled graphics processing units (GPU). Known as GLitch, it appears that at the time of publication only platforms with integrated GPUs - such as smartphones and laptops - are affected.
Report a cyber attack: call 0300 303 5222 or email [email protected]

This content has been archived

This article no longer conforms to NHS Digital's standards for cyber alerts, and may contain outdated or inaccurate information. Use of this information contained in this page is at your own risk

Summary

A new variant of the Rowhammer dynamic random-access-memory (DRAM) attack has been produced that targets WebGL-enabled graphics processing units (GPU). Known as GLitch, it appears that at the time of publication only platforms with integrated GPUs - such as smartphones and laptops - are affected.

Threat details

The proof-of-concept exploit takes advantage of the JavaScript WebGL API's timing calls function to determine a targeted device's DRAM layout before using the it's GPU to perform the Rowhammer attack. The researchers who created the exploit claim GPUs are typically less secure than central processing units (CPU) and as such are more easily controlled by an attacker.

For further information:


Remediation steps

Type Step
As WebGL is a web-based API, this vulnerability may only be exploited through a web browser. Google Chrome, Microsoft Edge and Mozilla Firefox have all released updates that remove the specific call function used in this proof-of-concept. Users should update their affected browsers in line with their standard patching regime.

CVE Vulnerabilities

Last edited: 17 February 2020 12:43 pm