Topics Tools Books & Guides Talk to Securafy

Knowledge Hub / IT Operations

IT Operations

Hot Pixels: A New CPU Data Theft Attack

Hot Pixels: A New CPU Data Theft Attack

Randy Hall By Randy Hall Updated Jul 2024 2 min read Share

A research team at Georgia Tech discovered a new threat called "Hot Pixels." It is a type of online attack where hackers can find out what websites have been visited by looking at the colors on the screen. They use special programs to do this and can find out the colors of most pixels. That is possible by studying patterns in how certain parts of the computer behave. Specifically, those parts that help produce images (GPUs) and compact computer systems (SoCs). Hot Pixels can extract information from a user's browser, including their browsing history, so business owners need to be more aware of these new cyber threats to avoid being affected by them.

How Hot Pixel Attacks Work

Researchers learned that modern CPUs have issues with power use and heat, especially at high processing speeds. This creates patterns that can be used to pull out data from webpages on Safari and Chrome.  Internal sensor measurements can be read using certain software. That’s how hackers can get right 94% of the information on a computer.

Studying frequency, power, and temperature on modern computers, the researchers found that data from processors that are passive can be read by looking at frequency and power. Meanwhile, those that are actively cooled leak information through temperature and power. The researchers focused on arm-based SoCs, GPUs, and CPUs as they're the most common. They have informed concerned tech giants about the issue and they are working to make their products safer.

Understanding the findings of this research can help business owners prevent these types of attacks.

A Reminder to Businesses to Update Security Protocols

Currently, there isn't an conclusive effective security measures to prevent hot pixel attacks yet. For now, business owners should focus on learning about the complexities of hot pixel attacks and staying updated on developments. That way, they can build better defenses against this threat and protect sensitive information.

Join The Conversation

Have a question or perspective on this topic? Add it below.

Randy Hall

About The Author

Randy Hall · CEO & Founder

Randy Hall is the CEO and Founder of Securafy, with decades of experience helping organizations make smarter, safer decisions about technology.

A frequent speaker and instructor at national IT events, Randy has advised thousands of organizations, from startups and SMBs to large enterprises and U.S. government entities, on secure, practical technology adoption. He writes about the decisions business leaders are often expected to make without enough context, including cybersecurity, compliance, AI, cyber insurance, IT strategy, and business resilience.

Outside the office, you’ll often find Randy on Lake Erie enjoying time on his 38-foot Chris-Craft.

Writes about: Cybersecurity strategy, compliance, AI security, business resilience, cyber insurance, SMB risk, IT leadership

More From This Author →

Get Practical Cybersecurity Field Notes

Monthly cybersecurity, compliance, and IT strategy updates from Securafy, written for business owners who need clear next steps.

  • Practical security tips from our Cyber Security Drip series
  • The Securafy Times, our monthly roundup on compliance and IT strategy
  • Occasional updates on new tools, guides, and research
  • No spam — unsubscribe anytime