Pixnapping Attack Lets Attackers Steal 2FA on Android
ID: 8e512ff9-33f5-5f8e-882d-ceedffedf434
STIX ID: report--8e512ff9-33f5-5f8e-882d-ceedffedf434
Feed Name: Dark Reading
Pixnapping is a proof-of-concept Android side-channel attack that uses Android APIs and a hardware timing channel to force and read pixels rendered by other apps or websites, enabling theft of displayed secrets such as 2FA codes, emails, and messages. Researchers demonstrated successful extraction from apps (Google Authenticator, Signal, Venmo) and websites (Gmail) on multiple Google Pixel and Samsung models; Google released a partial mitigation and plans further patches, but researchers found a workaround and no comprehensive vendor mitigation is confirmed. Although exploitation requires specific device conditions and an open app and there are no reported in-the-wild cases, the vulnerability poses notable risk until fully mitigated.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
