logo

New Android Pixnapping attack steals MFA codes pixel-by-pixel

ID: 872e99b6-1216-5e60-bbcc-511f7ab14f4a

STIX ID: report--872e99b6-1216-5e60-bbcc-511f7ab14f4a

Feed Name: Bleeping Computer

Threat Score
72/100

Date Published: 2025-10-14

Date Updated: 2026-07-18

Author: Bill Toulas

...
...

Researchers disclosed “Pixnapping,” a high‑impact Android side‑channel attack that lets a permissionless malicious app isolate and enlarge specific screen pixels (via intent abuse, masked activities, and a GPU compression side channel) to reconstruct sensitive content — including Google Authenticator 2FA codes — on many modern devices (Pixel and Samsung, Android 13–16). Google released an initial mitigation (CVE-2025-48561) that was bypassed; a more complete patch is expected in the December 2025 Android security update. The attack is technically sophisticated, works across multiple devices and apps (Signal, Gmail, Maps, Venmo), and can exfiltrate 2FA codes in under 30 seconds in optimized tests, though no in-the-wild abuse on Google Play was observed at publication.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.