Tools

News

Notícias

Classificados

Cursos

Broker

IPv4:
IPv6:
UpOrDown
Ping
MTR
MTU Detect
Portscan
DNS
HTTP/SSL
My IP
IP Calc & Sum

Pixnapping Threat Expands to Android 2FA

Image © Arstechnica
A new Android threat dubbed Pixnapping can covertly siphon 2FA codes, private messages, and other sensitive data from screen content after a victim installs a malicious app with no special permissions.

A new attack codenamed Pixnapping could quietly extract 2FA codes, private messages, and location timelines from Android screens in under 30 seconds. Researchers say the malicious app used for the attack requires no system permissions, yet can read data that other apps display on screen.

The technique hinges on triggering targeted apps to reveal sensitive data, then reading that data by manipulating rendering across specific screen pixels and using a side-channel to translate those pixels into characters or digits. The researchers emphasize that content visible on the screen—such as chat messages or one-time codes—can be read, while information that never appears on-screen remains inaccessible.

Pixnapping has been demonstrated on Google Pixel devices and Samsung Galaxy S25 phones, with researchers noting that porting the method to other Android models would be possible with additional effort. Google has released mitigations in recent updates, but the study authors contend that a modified version can still work even on patched devices.

The attack is reminiscent of the GPU.zip side-channel from 2023, which exploited rendering pipelines to reveal sensitive visuals across websites. Unlike software sandbox fixes, these pixel- or frame-level side channels are difficult to eliminate completely, and browsers previously blocked related exploits by restricting iframe use.

For users, the takeaway is clear: avoid installing apps from untrusted sources, apply security updates promptly, and monitor for unusual authentication activity. Ongoing research aims to strengthen defenses against pixel-based data exfiltration.

 

Arstechnica

Notícias relacionadas

Anatel mira licitação para compromissos da Oi
Anatel mantém multa milionária contra Mercado Livre
Fim das concessões: Claro migra
Inter Cel comemora quatro anos com planos renovados
Anatel define fornecedor para substituir a Oi
Anatel aprova prévia para retomada da FiBrasil pela Vivo

O ISP.Tools sobrevive graças aos anúncios.

Considere desativar seu bloqueador de anúncios.
Prometemos não ser intrusivos.

Consentimento de cookies

Usamos cookies para melhorar sua experiência em nosso site.

Ao usar nosso site, você concorda com os cookies. Saiba mais sobre o site