Ars Technica reports that Android devices, such as Samsung's S25 phones and Google's Pixel phones, could have their private information, including chat messages, two-factor authentication codes, and location timelines, pilfered in less than 30 seconds through the new Pixnapping attack.Threat actors could facilitate the compromise through a malicious app invoking Android APIs to call on apps they wish to compomise, with information from such apps channeled to the Android rendering pipeline that renders the apps' pixels, findings from researchers at the University of California, Berkeley, the University of California, San Diego, the University of Washington, and the Carnegie Mellon University, who developed the attack technique, revealed.Graphical operations selecting the coordinates of targeted pixels and measuring the time necessary for every coordinate are then conducted by Pixnapping before it reconstructs the images delivered to the rendering pipeline. Google, whose partial fix for the issue was found to be inadequate, will be releasing another patch by December.
Application security, Data Security

New Pixnapping attack threatens sensitive Android app data

(Adobe Stock Images)

Related Events
Get daily email updates
SC Media's daily must-read of the most current and pressing daily news
You can skip this ad in 5 seconds



