2025 · NDSS · CSS and email fingerprinting
Leon Trampert, Daniel Weber, Lukas Gerlach, Christian Rossow, Michael Schwarz
Modern CSS is expressive enough to reveal information about browsers and email clients without JavaScript. This paper maps that attack surface systematically and evaluates two approaches to mitigating the underlying leakage.
2025 · uASC · Font-based side channels
Leon Trampert, Michael Schwarz
TrueType fonts contain a small instruction language that normally adjusts glyph rendering. This paper shows that those instructions can instead perform cache attacks, enabling website fingerprinting and observation of PDF reading behavior without JavaScript.
2025 · WWW · Web APIs and peripheral security
Leon Trampert, Lorenz Hetterich, Lukas Gerlach, Mona Schappert, Christian Rossow, Michael Schwarz
WebHID, WebUSB, Web Serial, and Web MIDI give websites direct access to external devices. This paper studies the resulting trust-boundary shift and demonstrates how vulnerable device interfaces can enable firmware replacement and full system compromise.