BTC NOON
  • Home
  • Cryptocurrency
  • Bitcoin
  • Ethereum
  • Blockchain
  • Regulations
  • Altcoin
  • DeFi
  • Web 3.0
No Result
View All Result
BTC NOON
No Result
View All Result
Home Business

Security Hole Found in Google Pixel Devices: Redacted Photos Recovered

Xiao Chen Sun by Xiao Chen Sun
March 23, 2023
in Business
0
Security Hole Found in Google Pixel Devices: Redacted Photos Recovered
74
SHARES
1.2k
VIEWS
Share on FacebookShare on Twitter

A dangerous security hole has been discovered in the default screenshot editing application on Google’s flagship smartphone, Google Pixel.

You might also like

TikTok US Ban Threatens Small Businesses, Creators and Entertainment Industry

Twitter Poll Eligibility Limited to Verified Accounts From April 15, Says Musk

BAYC Owner Yuga Hosts Second Otherside Metaverse Experience

The editing utility called ‘Markup’ allows images to become partially “unedited,” which may reveal details the sender wanted to hide.

“Introducing acropalypse: a serious privacy vulnerability in the Google Pixel’s inbuilt screenshot editing tool, Markup, enabling partial recovery of the original, unedited image data of a cropped and/or redacted screenshot,” tweeted Simon Aaarons, the reverse engineer who discovered the vulnerability along with David Buchanan.

Although Google has fixed the vulnerability, its impact is still far-reaching, particularly for the edited screenshots that were shared before the update.

According to Aaarons’ Twitter thread, a vulnerability known as the “acropalypse” flaw can partially recover edited PNG screenshots in Markup. This poses a risk for users who may have used the tool to crop or scribble out sensitive information, such as their personal details or credit card number, as a malicious actor could exploit the flaw to reverse the changes and obtain the hidden information.

According to Aarons and Buchanan, the flaw is due to Markup’s behavior of storing the original screenshot in the same file location as the edited one, without deleting the original version. As explained, if the edited version of the screenshot has a smaller file size than the original, “the trailing portion of the original file is left behind, after the new file is supposed to have ended.”

“This bug is a bad one. You can patch it, but you can’t easily un-share all the vulnerable images you may have sent. The bug existed for about 5 years before being patched, which is mind-blowing given how easy it is to spot when you look closely at an output file,” wrote Buchanan.

iPhone has a feature to remove Medadata

The problem only exists in the Google Pixel devices, whereas Apple’s iPhone has the feature to share files with or without metadata.

iPhones provide three options: “save without metadata, share without metadata, and share with metadata.”

Although some websites like Twitter re-process the images uploaded on their platforms to remove the flaw, others like Discord do not. Discord only addressed the vulnerability with a recent update released on January 17th, meaning any edited images shared before that date may still be at risk.

It remains uncertain whether there are any other sites or applications that are affected by the flaw. Buchanan has explained this issue with technical details in a blog post.

“IMHO, the takeaway here is that API footguns should be treated as security vulnerabilities,” wrote Buchanan.

The discovery of this flaw occurred shortly after Google’s security team uncovered a vulnerability in the Samsung Exynos modems found in devices like the Pixel 6, Pixel 7, and specific models of the Galaxy S22 and A53.

The security flaw could enable hackers to remotely compromise devices using just the phone number of the victim. Google has released a patch for this issue in its March update, but the update is not yet available for the Pixel 6, 6 Pro, and 6A devices.


This article is originally from MetaNews.

Share30Tweet19
Xiao Chen Sun

Xiao Chen Sun

Recommended For You

TikTok US Ban Threatens Small Businesses, Creators and Entertainment Industry

by Xiao Chen Sun
March 30, 2023
0
TikTok US Ban Threatens Small Businesses, Creators and Entertainment Industry

China-owned video-sharing platform TikTok is on the verge of a nationwide ban in the United States. A possible ban will force more than 150 million users in the...

Read more

Twitter Poll Eligibility Limited to Verified Accounts From April 15, Says Musk

by Xiao Chen Sun
March 30, 2023
0
Twitter Poll Eligibility Limited to Verified Accounts From April 15, Says Musk

Twitter will be implementing a major change in its recommendation system, Elon Musk has announced. Starting from April 15, only verified accounts will be eligible to appear in...

Read more

BAYC Owner Yuga Hosts Second Otherside Metaverse Experience

by Xiao Chen Sun
March 30, 2023
0
BAYC Owner Yuga Hosts Second Otherside Metaverse Experience

This past weekend Yuga Labs, the owner of popular NFT collection Bored Ape Yacht Club, hosted the ‘Second Trip’ to its Otherside metaverse, with thousands of users taking...

Read more

BAYC Owner Yuga Hosts Second Otherside Metaverse Experience

by Xiao Chen Sun
March 28, 2023
0
BAYC Owner Yuga Hosts Second Otherside Metaverse Experience

This past weekend Yuga Labs, the owner of popular NFT collection Bored Ape Yacht Club, hosted the ‘Second Trip’ to its Otherside metaverse, with thousands of users taking...

Read more

Block Share Price Plummets After Hindenburg Fraud Accusations

by Xiao Chen Sun
March 26, 2023
0
Block Share Price Plummets After Hindenburg Fraud Accusations

Jack Dorsey’s company Block saw a 20.13% drop in share price after Hindenburg Research accused it of allowing criminal activity and inflating Cash App’s user base. “Our 2-year...

Read more
Next Post
Podcast Created Entirely with AI Debuts on Spotify, Apple

Podcast Created Entirely with AI Debuts on Spotify, Apple

Related News

Non-biased Interview Part 3 – GoodShibe of DOGEcoin Community – Financial Underground Kingdom

Non-biased Interview Part 3 – GoodShibe of DOGEcoin Community – Financial Underground Kingdom

March 10, 2023
Russian crypto advocates urge Putin to stop regulatory hostility

Russian crypto advocates urge Putin to stop regulatory hostility

March 8, 2023
IMF examines CBDC design in context of Islamic banking, finds some risks magnified

IMF examines CBDC design in context of Islamic banking, finds some risks magnified

March 20, 2023

Browse by Category

  • Altcoin
  • Altcoin News
  • Altcoins
  • Artificial Intelligence
  • Bitcoin
  • Blockchain
  • Business
  • Cryptocurrencies
  • Cryptocurrency
  • Culture
  • DeFi
  • Economy
  • Education
  • Ethereum
  • Featured
  • Governance
  • News
  • Regulations
  • Uncategorized
  • Web 3.0

Find Via Tags

Altcoin Analyst Bank bill Binance Bitcoin Blockchain Blog BTC Chain Coinbase Crypto data DeFi digital DOGEcoin ETH Ethereum Exchange Exchanges Fees finance Foundation FTX Heres high IBM Investors Launches market million Network NFT Platform Polygon Price Protocol Regulatory Report SEC Token Top Trading Upgrade Web3

Categories

  • Altcoin
  • Altcoin News
  • Altcoins
  • Artificial Intelligence
  • Bitcoin
  • Blockchain
  • Business
  • Cryptocurrencies
  • Cryptocurrency
  • Culture
  • DeFi
  • Economy
  • Education
  • Ethereum
  • Featured
  • Governance
  • News
  • Regulations
  • Uncategorized
  • Web 3.0

Recommended

  • Bitcoin Exchange Inflows Mostly Coming From Loss Holders, Weak Hands Exiting?
  • IBM Cloud releases 2023 IBM Cloud for Financial Services Agreed-Upon Procedures (AUP) Report
  • Will Wall Street Memes Be the Next Pepe as PEPE Price Continues to Struggle?
  • Devconnect: 18-25 April 2022 in Amsterdam
  • Avalanche: How DeFi and stablecoins improved the network

© 2023 BTC NOON | All Rights Reserved

No Result
View All Result
  • Home
  • Cryptocurrency
  • Bitcoin
  • Ethereum
  • Blockchain
  • Regulations
  • Altcoin
  • DeFi
  • Web 3.0

© 2023 BTC NOON | All Rights Reserved

Are you sure want to unlock this post?
Unlock left : 0
Are you sure want to cancel subscription?