Web Hack List

Collected research

Practical Memory Deduplication Attacks in Sandboxed JavaScript

Operating systems and hypervisors merge identical physical memory pages, and the merge is observable as a slow write to a page that was deduplicated. Timing writes from ordinary sandboxed JavaScript in a visited web page discloses which programs, program versions and websites the victim currently has open, across virtual machine boundaries and on Windows and Android.

Record

Researcher
Daniel Gruss, David Bidner and Stefan Mangard
Published by
gruss.cc
Format
Whitepaper
Topic
Server

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of Daniel Gruss, David Bidner and Stefan Mangard, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .