New Android Pixnapping attack steals MFA codes pixel-by-pixel
ID: 872e99b6-1216-5e60-bbcc-511f7ab14f4a
STIX ID: report--872e99b6-1216-5e60-bbcc-511f7ab14f4a
Feed Name: Bleeping Computer
Researchers disclosed “Pixnapping,” a high‑impact Android side‑channel attack that lets a permissionless malicious app isolate and enlarge specific screen pixels (via intent abuse, masked activities, and a GPU compression side channel) to reconstruct sensitive content — including Google Authenticator 2FA codes — on many modern devices (Pixel and Samsung, Android 13–16). Google released an initial mitigation (CVE-2025-48561) that was bypassed; a more complete patch is expected in the December 2025 Android security update. The attack is technically sophisticated, works across multiple devices and apps (Signal, Gmail, Maps, Venmo), and can exfiltrate 2FA codes in under 30 seconds in optimized tests, though no in-the-wild abuse on Google Play was observed at publication.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
