• Home
  • About
  • Contact Us
  • Privacy Policy

Technic News

The Latest in Technology

  • New Technology
  • Cool Gadgets
  • Latest Tech & Gadgets
  • Tech & Gadget Reviews
  • Tech & Gadget News
  • Gadgets Shop

Google Pixel vulnerability allows bad actors to undo Markup screenshot edits and redactions

When Google began rolling out Android’s March security patch earlier this week, the company addressed a “High” severity vulnerability involving the Pixel’s Markup screenshot tool. Over the weekend, Simon Aarons and David Buchanan, the reverse engineers who discovered CVE-2023-21036, shared more information about the security flaw, revealing Pixel users are still at risk of their older images being compromised due to the nature of Google’s oversight.

In short, the “aCropalypse” flaw allowed someone to take a PNG screenshot cropped in Markup and undo at least some of the edits in the image. It’s easy to imagine scenarios where a bad actor could abuse that capability. For instance, if a Pixel owner used Markup to redact an image that included sensitive information about themselves, someone could exploit the flaw to reveal that information. You can find the technical details on Buchanan’s blog.

Introducing acropalypse: a serious privacy vulnerability in the Google Pixel’s inbuilt screenshot editing tool, Markup, enabling partial recovery of the original, unedited image data of a cropped and/or redacted screenshot. Huge thanks to @David3141593 for his help throughout! pic.twitter.com/BXNQomnHbr

— Simon Aarons (@ItsSimonTime) March 17, 2023

According to Buchanan, the flaw has existed for about five years, coinciding with the release of Markup alongside Android 9 Pie in 2018. And therein lies the problem. While March’s security patch will prevent Markup from compromising future images, some screenshots Pixel users may have shared in the past are still at risk.

It’s hard to say how concerned Pixel users should be about the flaw. According to a forthcoming FAQ page Aarons and Buchanan shared with 9to5Google and The Verge, some websites, including Twitter, process images in such a way that someone could not exploit the vulnerability to reverse edit a screenshot or image. Users on other platforms aren’t so lucky. Aarons and Buchanan specifically identify Discord, noting the chat app did not patch out the exploit until its recent January 17th update. At the moment, it’s unclear if images shared on other social media and chat apps were left similarly vulnerable.

Google did not immediately respond to Engadget’s request for comment and more information. The March security update is currently available on the Pixel 4a, 5a, 7 and 7 Pro, meaning Markup can still produce vulnerable images on some Pixel devices. It’s unclear when Google will push the patch to other Pixel devices. If you own a Pixel phone without the patch, avoid using Markup to share sensitive images.

This article originally appeared on Engadget at https://www.engadget.com/google-pixel-vulnerability-allows-bad-actors-to-undo-markup-screenshot-edits-and-redactions-195322267.html?src=rss

Brought to you by USA Today Read the rest of the article here.

  • Facebook
  • Twitter
  • Pinterest

Filed Under: Tech & Gadget News

  • Email
  • Facebook
  • YouTube

www.sicherversichert.de

www.service-hotel-24.com

www.virtutea.com

www.my-fly.club 

www.1-2-holiday.com

www.women-fashion-online.com

www.amer.de

www.cupado.de

Recent Posts

  • CISA releases an open-source Python-based utility to detect signs of malicious activity in Microsoft cloud environments (Sergiu Gatlan/BleepingComputer) March 23, 2023
  • Quantum computing startup Strangeworks raised a $24M Series A led by Hitachi Ventures with participation from IBM and Raytheon Technologies (SiliconHills) March 23, 2023
  • Messages in Binance’s public chatrooms show some employees and support volunteers helping customers bypass China’s crypto ban, including evading its KYC checks (Rohan Goswami/CNBC) March 23, 2023
  • Warsaw-based Vue Storefront, which lets front-end developers build composable e-commerce sites, raised a $20M Series A extension led by Felix Capital (Ingrid Lunden/TechCrunch) March 23, 2023
  • Twitter plans to wind down its legacy verified program and remove legacy verified checkmarks starting on April 1, 2023 (Todd Spangler/Variety) March 23, 2023

Copyright © 2023 · Designed by Amaraq Websites

We use cookies on our website to give you the most relevant experience by remembering your preferences and repeat visits. By clicking “Accept”, you consent to the use of ALL the cookies.
Cookie settingsACCEPT
Manage consent

Privacy Overview

This website uses cookies to improve your experience while you navigate through the website. Out of these, the cookies that are categorized as necessary are stored on your browser as they are essential for the working of basic functionalities of the website. We also use third-party cookies that help us analyze and understand how you use this website. These cookies will be stored in your browser only with your consent. You also have the option to opt-out of these cookies. But opting out of some of these cookies may affect your browsing experience.
Necessary
Always Enabled

Necessary cookies are absolutely essential for the website to function properly. This category only includes cookies that ensures basic functionalities and security features of the website. These cookies do not store any personal information.

Non-necessary

Any cookies that may not be particularly necessary for the website to function and is used specifically to collect user personal data via analytics, ads, other embedded contents are termed as non-necessary cookies. It is mandatory to procure user consent prior to running these cookies on your website.