By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
PulseReporterPulseReporter
  • Home
  • Entertainment
  • Lifestyle
  • Money
  • Tech
  • Travel
  • Investigations
Reading: Google Researchers Discovered Practically a Dozen Flaws in Widespread Qualcomm Software program for Cell GPUs
Share
Notification Show More
Font ResizerAa
PulseReporterPulseReporter
Font ResizerAa
  • Home
  • Entertainment
  • Lifestyle
  • Money
  • Tech
  • Travel
  • Investigations
Have an existing account? Sign In
Follow US
  • Advertise
© 2022 Foxiz News Network. Ruby Design Company. All Rights Reserved.
PulseReporter > Blog > Tech > Google Researchers Discovered Practically a Dozen Flaws in Widespread Qualcomm Software program for Cell GPUs
Tech

Google Researchers Discovered Practically a Dozen Flaws in Widespread Qualcomm Software program for Cell GPUs

Pulse Reporter
Last updated: August 10, 2024 3:20 am
Pulse Reporter 9 months ago
Share
Google Researchers Discovered Practically a Dozen Flaws in Widespread Qualcomm Software program for Cell GPUs
SHARE


Demand for graphics processing models or GPUs has exploded in current years as video rendering and synthetic intelligence methods have expanded the necessity for processing energy. And whereas a lot of the most seen shortages (and hovering inventory costs) relate to top-tier PC and server chips, cell graphics processors are the model that everybody with a smartphone is utilizing on a regular basis. So vulnerabilities in these chips or how they’re applied can have real-world penalties. That is precisely why Google’s Android vulnerability looking purple group set its sights on open-source software program from the chip large Qualcomm that is broadly used to implement cell GPUs.

On the Defcon safety convention in Las Vegas on Friday, three Google researchers introduced greater than 9 vulnerabilities—now patched—that they found in Qualcomm’s Adreno GPU, a set of software program used to coordinate between GPUs and an working system like Android on Qualcomm-powered telephones. Such “drivers” are essential to how any laptop is designed and have deep privileges within the kernel of an working system to coordinate between {hardware} peripherals and software program. Attackers may exploit the issues the researchers discovered to take full management of a tool.

For years, engineers and attackers alike have been most centered on potential vulnerabilities in a pc’s central processing unit (CPU) and have optimized for effectivity on GPUs, leaning on them for uncooked processing energy. However as GPUs turn out to be extra central to every little thing a tool does on a regular basis, hackers on each ends of the spectrum are taking a look at how GPU infrastructure might be exploited.

“We’re a small group in comparison with the massive Android ecosystem—the scope is simply too huge for us to cowl every little thing, so we have now to determine what may have essentially the most affect,” says Xuan Xing, supervisor of Google’s Android Pink Group. “So why did we deal with a GPU driver for this case? It is as a result of there’s no permission required for untrusted apps to entry GPU drivers. This is essential, and I believe will appeal to a number of attackers’ consideration.”

Xing is referring to the truth that purposes on Android telephones can discuss to the Adreno GPU driver immediately with “no sandboxing, no further permission checks,” as he places it. This does not in itself give purposes the power to go rogue, however it does make GPU drivers a bridge between the common components of the working system (the place knowledge and entry are rigorously managed), and the system kernel, which has full management over the complete system together with its reminiscence. “GPU drivers have all kinds of highly effective features,” Xing says. “That mapping in reminiscence is a robust primitive attackers wish to have.”

The researchers say the vulnerabilities they uncovered are all flaws that come out of the intricacies and complex interconnections that GPU drivers should navigate to coordinate every little thing. To take advantage of the issues, attackers would want to first set up entry to a goal system, maybe by tricking victims into side-loading malicious apps.

“There are a number of transferring components and no entry restrictions, so GPU drivers are readily accessible to just about each software,” says Eugene Rodionov, technical chief of the Android Pink Group. “What actually makes issues problematic right here is complexity of the implementation—that’s one merchandise which accounts for numerous vulnerabilities.”

Qualcomm launched patches for the issues to “authentic gear producers” (OEMs) that use Qualcomm chips and software program within the Android telephones they make. “Relating to the GPU points disclosed by Android Safety Pink Group, patches had been made obtainable to OEMs in Could 2024,” a Qualcomm Spokesperson tells WIRED. “We encourage finish customers to use safety updates from system makers as they turn out to be obtainable.”

The Android ecosystem is complicated, and patches should transfer from a vendor like Qualcomm to OEMs after which get packaged by every particular person system maker and delivered to customers’ telephones. This trickle-down course of generally implies that gadgets could be left uncovered, however Google has spent years investing to enhance these pipelines and streamline communication.

Nonetheless, the findings are one more reminder that GPUs themselves and the software program supporting them have the potential to turn out to be a important battleground in laptop safety.

As Rodionov places it, “combining excessive complexity of the implementation with extensive accessibility makes it a really attention-grabbing goal for attackers.”

You Might Also Like

BuzzFeed is promoting Sizzling Ones

YouTuber MrBeast shares first 10 minutes of controversial new recreation present

Andor’s second season hits Disney Plus in April

This AI assistant app helps with all of your busywork for £30

20 Greatest Items for Girls Who Are Over This Actuality (2025)

Share This Article
Facebook Twitter Email Print
Previous Article The Final Information to Carry-On Weight Limits The Final Information to Carry-On Weight Limits
Next Article Suggestions for a More healthy, Longer Life Suggestions for a More healthy, Longer Life
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Weekly Newsletter

Subscribe to our newsletter to get our newest articles instantly!

More News

Apple blocks Fortnite’s return to the U.S. App Retailer and Epic Video games Retailer in EU, regardless of ruling
Apple blocks Fortnite’s return to the U.S. App Retailer and Epic Video games Retailer in EU, regardless of ruling
16 minutes ago
Fortune’s 2025 CEO Survey reveals growing pessimism
Fortune’s 2025 CEO Survey reveals growing pessimism
23 minutes ago
Common Disney Followers Can Title 10 Of These Newer Disney Characters, However Solely Elite Followers Can Title Extra Than 20
Common Disney Followers Can Title 10 Of These Newer Disney Characters, However Solely Elite Followers Can Title Extra Than 20
52 minutes ago
The Finest Items for Guide Lovers (2025)
The Finest Items for Guide Lovers (2025)
1 hour ago
Which celeb's vibe actually simply makes you cringe?
Which celeb's vibe actually simply makes you cringe?
2 hours ago

About Us

about us

PulseReporter connects with and influences 20 million readers globally, establishing us as the leading destination for cutting-edge insights in entertainment, lifestyle, money, tech, travel, and investigative journalism.

Categories

  • Entertainment
  • Investigations
  • Lifestyle
  • Money
  • Tech
  • Travel

Trending

  • Apple blocks Fortnite’s return to the U.S. App Retailer and Epic Video games Retailer in EU, regardless of ruling
  • Fortune’s 2025 CEO Survey reveals growing pessimism
  • Common Disney Followers Can Title 10 Of These Newer Disney Characters, However Solely Elite Followers Can Title Extra Than 20

Quick Links

  • About Us
  • Contact Us
  • Privacy Policy
  • Terms Of Service
  • Disclaimer
2024 © Pulse Reporter. All Rights Reserved.
Welcome Back!

Sign in to your account