In recent years, an Acropalypse vulnerability in the Google Pixel's Markup tool posed a serious security threat, allowing malicious users to partially reveal the content of edited or manipulated images and screenshots – even those that had their contents cropped or hidden!

See also: Google Pixel 7a: Leak shows us the design of the new device!
The Markup tool is a built-in image editor that allows you to edit, crop, and change images on a Google Pixel device.
Security researchers Simon Aarons and David Buchanan have uncovered a major vulnerability that had been hidden for five years. Dubbed “Acropalypse,” the vulnerability can still be used to extract sensitive information from edited images, the researchers said on Twitter.
Aaron showed how they were able to exploit the Acropalypse vulnerability to recover an image – uploaded to Discord – of a partially obscured credit card using the Markup tool. Despite using the black marker mode, Aaron was able to restore every detail!
After running the photo through their Acropalypse exploit, they recovered the original image, as shown below.

The researchers also made the screenshot recovery utility Acropalypse publicly available so Pixel owners can check if their edited photos can be salvaged.
Researchers reported the flaw to Google in January 2023, and the company fixed it via an update released on March 13, 2023, tracking it as CVE-2023-21036.
The problem is believed to stem from the way the image file was opened for editing, resulting in truncated data remaining in a saved image and making it possible to restore almost 80% of its original format.
See also: Android 13 QPR2: Update arrives for Google Pixel 7
Data extracted using Pixel's Markup tool could be exposed if the vulnerability is not addressed, resulting in confidential information being leaked online.
If you publish on platforms that do not reduce the quality of the posted media, then any sensitive information will remain intact.
Although additional details about the issue will soon be made available on a separate website, they are not yet accessible at this time.
In blog , Buchanan revealed further technical details about the issue.
There's not much you can do!
Despite Google's efforts to fix the problem with a recent software update, all photos shared in the last five years are still vulnerable to the Acropalypse attack – a bug that cannot be fixed retroactively.
This glitch could have far-reaching consequences for users who uploaded screenshots with confidential information hidden using Markup.
Unfortunately, the issue affects all Pixel models running Android 9 Pie and later, when the Markup tool was introduced, and until the February 2023 security patch
See also: Google Pixel 8 Pro: New leaks show a new feature
Finally, Acropalypse has the potential to affect non-Pixel phones running third-party Android distributions that exploit the Markup tool when editing screenshots/images.
Information source: bleepingcomputer.com
