A side-channel information leakage vulnerability exists in the graphics component of Google Chrome prior to version 87.0.4280.66. This flaw allows a remote attacker to craft a malicious HTML page that can exploit the graphics subsystem to leak cross-origin data, bypassing same-origin policy protections.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
3 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos.
Repository is a PoC for CVE-2020-16012 (Canvas drawImage timing side-channel) intended to recover an image (notably a QR-code) by measuring per-pixel rendering timing and reconstructing it server-side. Structure and purpose: - README.md: Explains setup. References running an old Chromium snapshot (Chrome 83) with GPU/rasterizer disabled and no sandbox, and running a Python server on port 7000. Includes a full client-side script snippet showing the measurement and exfiltration logic. - server.py: Flask + flask_cors server that accepts pixel/timing data and reconstructs an image. - POST /: accepts single pixel JSON {x,y,rgb} (rgb is timing), appends to pixels_log.txt. - POST /batch: accepts {pixels:[{x,y,rgb},...]} and appends all to pixels_log.txt. - GET /generate-image: generates a PNG from the log and returns its path. - GET /get-latest-image: returns the latest generated PNG (or generates one if missing). - GET /auto-save: generates/saves a PNG and returns JSON with the saved path. - Image generation uses numpy + Pillow: builds a grayscale array, computes a median-based threshold (median*0.84) and binarizes to black/white, then saves to output/qrcode_<timestamp>.png. - requirements.txt: flask, flask_cors, Pillow, numpy. - index.html.bak: appears to be the original PoC HTML shell for “QR Code Recovery” (minimal page; likely where the JS was originally embedded). - index.html: unrelated “TechInsider” blog-style page; likely a decoy/placeholder and not part of the PoC logic. Exploit capabilities: - Browser-side: repeatedly calls CanvasRenderingContext2D.drawImage() for each pixel coordinate (75x75) with many iterations (Iters=200) and uses performance.now() timing deltas as a side-channel signal. - Network exfiltration: sends measurements to a configurable server URL (example hardcoded to 192.168.0.26:7000) using fetch(), primarily via batched POSTs to /batch. - Server-side: logs received measurements, reconstructs and saves an image, and exposes endpoints to trigger generation and retrieve the latest image. Overall, this is an operational PoC demonstrating side-channel leakage and data collection/reconstruction rather than a traditional RCE exploit; it requires a vulnerable browser environment and user interaction to run the HTML.
This repository demonstrates a proof-of-concept (POC) side-channel attack targeting Google Chrome version 83 on Linux. The attack leverages timing differences in canvas pixel rendering to recover image data (such as a QR code) from a browser context. The repository consists of a client-side component (JavaScript embedded in an HTML file) that measures pixel rendering times and sends the data to a Python Flask server running locally on port 7000. The server collects the timing data, reconstructs the image, and saves it as a PNG file. The README provides detailed setup instructions, including the required Chrome version and launch parameters. The main code files are 'server.py' (the Flask server) and the JavaScript code (provided in the README and likely in a separate HTML file, not included in the file list). The attack vector is browser-based, requiring the user to open a specially crafted HTML file in a vulnerable Chrome version. The endpoints used for data exfiltration and image retrieval are all local HTTP endpoints. The exploit is a POC and does not include weaponized or automated payloads beyond the demonstration of the side-channel technique.
This repository provides proof-of-concept (PoC) code for CVE-2020-16012, a side channel vulnerability in the CanvasRenderingContext2D.drawImage() implementation in Firefox and Chromium. The repository contains two main directories: 'benchmark', which includes code and data for measuring and recording timing differences in image drawing operations, and 'exploit', which contains an HTML/JavaScript exploit that demonstrates silhouette recovery of a cross-origin image. The exploit works by measuring the time taken to draw individual pixels from a cross-origin image onto a canvas, exploiting timing differences to reconstruct the image's silhouette. The main target is a cross-origin image hosted at 'https://p.2038.io/secret2.png'. The exploit is a browser-based side-channel attack and is a proof-of-concept, not a weaponized exploit. The code is intended for research and demonstration purposes, targeting Firefox 76 and Chromium 83 on Linux with CPU rendering.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
1 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.