Friday, June 2, 2023
DAPPS CLUB
  • Home
  • Cryptocurrency
  • Bitcoin
  • Ethereum
  • Blockchain
  • Altcoin
  • Litecoin
  • Metaverse
  • NFt
  • Regulations
No Result
View All Result
DAPPS CLUB
No Result
View All Result
Home Business

Security Hole Found in Google Pixel Devices: Redacted Photos Recovered

Lincoln Cavenagh by Lincoln Cavenagh
March 23, 2023
in Business
0
Security Hole Found in Google Pixel Devices: Redacted Photos Recovered
0
SHARES
1
VIEWS
Share on FacebookShare on Twitter

A dangerous security hole has been discovered in the default screenshot editing application on Google’s flagship smartphone, Google Pixel.

The editing utility called ‘Markup’ allows images to become partially “unedited,” which may reveal details the sender wanted to hide.

Related posts

TikTok US Ban Threatens Small Businesses, Creators and Entertainment Industry

TikTok US Ban Threatens Small Businesses, Creators and Entertainment Industry

March 30, 2023
Twitter Poll Eligibility Limited to Verified Accounts From April 15, Says Musk

Twitter Poll Eligibility Limited to Verified Accounts From April 15, Says Musk

March 30, 2023

“Introducing acropalypse: a serious privacy vulnerability in the Google Pixel’s inbuilt screenshot editing tool, Markup, enabling partial recovery of the original, unedited image data of a cropped and/or redacted screenshot,” tweeted Simon Aaarons, the reverse engineer who discovered the vulnerability along with David Buchanan.

Although Google has fixed the vulnerability, its impact is still far-reaching, particularly for the edited screenshots that were shared before the update.

According to Aaarons’ Twitter thread, a vulnerability known as the “acropalypse” flaw can partially recover edited PNG screenshots in Markup. This poses a risk for users who may have used the tool to crop or scribble out sensitive information, such as their personal details or credit card number, as a malicious actor could exploit the flaw to reverse the changes and obtain the hidden information.

According to Aarons and Buchanan, the flaw is due to Markup’s behavior of storing the original screenshot in the same file location as the edited one, without deleting the original version. As explained, if the edited version of the screenshot has a smaller file size than the original, “the trailing portion of the original file is left behind, after the new file is supposed to have ended.”

“This bug is a bad one. You can patch it, but you can’t easily un-share all the vulnerable images you may have sent. The bug existed for about 5 years before being patched, which is mind-blowing given how easy it is to spot when you look closely at an output file,” wrote Buchanan.

iPhone has a feature to remove Medadata

The problem only exists in the Google Pixel devices, whereas Apple’s iPhone has the feature to share files with or without metadata.

iPhones provide three options: “save without metadata, share without metadata, and share with metadata.”

Although some websites like Twitter re-process the images uploaded on their platforms to remove the flaw, others like Discord do not. Discord only addressed the vulnerability with a recent update released on January 17th, meaning any edited images shared before that date may still be at risk.

It remains uncertain whether there are any other sites or applications that are affected by the flaw. Buchanan has explained this issue with technical details in a blog post.

“IMHO, the takeaway here is that API footguns should be treated as security vulnerabilities,” wrote Buchanan.

The discovery of this flaw occurred shortly after Google’s security team uncovered a vulnerability in the Samsung Exynos modems found in devices like the Pixel 6, Pixel 7, and specific models of the Galaxy S22 and A53.

The security flaw could enable hackers to remotely compromise devices using just the phone number of the victim. Google has released a patch for this issue in its March update, but the update is not yet available for the Pixel 6, 6 Pro, and 6A devices.


This article is originally from MetaNews.

Previous Post

Are Tesla Bots Already Helping to Build Cars?

Next Post

Podcast Created Entirely with AI Debuts on Spotify, Apple

Next Post
Podcast Created Entirely with AI Debuts on Spotify, Apple

Podcast Created Entirely with AI Debuts on Spotify, Apple

RECOMMENDED NEWS

China unviels white paper to foster web3 development – Cryptopolitan

China unviels white paper to foster web3 development – Cryptopolitan

6 days ago
Ethereum Traders Scrambling For The Exits After Price Crash

Ethereum Traders Scrambling For The Exits After Price Crash

6 days ago
Boerse Stuttgart Stock Exchange Taps BaFIN License to Offer Crypto Custody

Boerse Stuttgart Stock Exchange Taps BaFIN License to Offer Crypto Custody

2 months ago
Blockchain.com Decides to Shut Down London-based Crypto Asset Management Wing

Blockchain.com Decides to Shut Down London-based Crypto Asset Management Wing

3 months ago

FOLLOW US

BROWSE BY CATEGORIES

  • Altcoin
  • Altcoin News
  • Altcoins
  • Artificial Intelligence
  • Bitcoin
  • Blockchain
  • Business
  • Cryptocurrencies
  • Cryptocurrency
  • Culture
  • Economy
  • Education
  • Ethereum
  • Featured
  • Governance
  • Litecoin
  • Metaverse
  • News
  • NFt
  • Regulations
  • Uncategorized

BROWSE BY TOPICS

Altcoin Analyst Bank Binance Bitcoin Blockchain Blog BTC Business coin Coinbase Crypto Cryptopolitan Data Digital DOGEcoin ETH Ethereum Exchange Foundation global Heres High Hypergrid IBM Investors Launches Litecoin LTC Market Network NFT Platform Price Rally regulatory REPORT SEC Solana TMS TMSN Top Trading Upgrade XRP

POPULAR NEWS

  • What is Cloud Mining and How Does it Work?

    What is Cloud Mining and How Does it Work?

    0 shares
    Share 0 Tweet 0
  • YOM brings Metaverse Mining to the Masses with MEXC Listing

    0 shares
    Share 0 Tweet 0
  • Educators Remain Metaverse Positive Despite Negative Media Spin

    0 shares
    Share 0 Tweet 0
  • Rise of AI-Powered Cheating: Challenges and Solutions for Educators

    0 shares
    Share 0 Tweet 0
  • ChatGPT is Being Used to Make ‘Quality Scams’

    0 shares
    Share 0 Tweet 0
Crypto markets by TradingView
Cryptocurrency Prices 

Recommended

  • Ex-Coinbase Executive and His Brother Reach Settlement With SEC on Crypto Insider-Trading Charges
  • Dogecoin (DOGE) Daily Transactions Spike 8,220% in May, According to IntoTheBlock
  • Bitcoin Taker Buy Sell Ratio Most Since Feb, What It Means

© 2023 Dapps Club | All Rights Reserved

No Result
View All Result
  • Home
  • Cryptocurrency
  • Bitcoin
  • Ethereum
  • Blockchain
  • Altcoin
  • Litecoin
  • Metaverse
  • NFt
  • Regulations

© 2023 Dapps Club | All Rights Reserved