HomeSecurityPixnapping attack: Malicious Android apps steal 2FA passwords

Pixnapping attack: Malicious Android apps steal 2FA passwords

devices from Google and Samsung have been found vulnerable to a side-channel attack, codenamed Pixnapping, that can be exploited to codes two-factor authentication (2FA) Google Maps timelines , and other sensitive data without users' knowledge (pixel-by-pixel).

Pixnapping

The attack was dubbed Pixnapping by a team of academics from the University of California (Berkeley), the University of Washington, the University of California (San Diego), and Carnegie Mellon University.

Pixnapping, in its basic form, is a pixel-stealing framework that targets Android devices, bypassing browser mitigations and extracting data from non-browser apps like Google Authenticator. It exploits Android APIs and a hardware side-channel, allowing a malicious app to use the technique to capture 2FA codes in less than 30 seconds.

See also: Vulnerability in Elastic Cloud Enterprise allows execution of malicious commands

Pixnapping attack

The study specifically focused on five devices from Google and Samsung running Android versions 13 to 16.While it is unclear whether Android devices from other manufacturers are vulnerable to Pixnapping, the underlying methodology required to execute the attack is present on all devices running the mobile operating system.

What makes the innovative attack significant is that any Android app can be used to execute it, even if the app doesn't have any special permissions attached to it via its manifest file. However, the attack assumes that the victim has been somehow convinced to install and launch the app.

Pixnapping attack: Malicious Android apps steal 2FA passwords

The side-channel that enables the Pixnapping attack is GPU.zip, which was discovered by researchers in September 2023. The attack essentially exploits a compression feature in modern integrated GPUs (iGPUs) to perform cross-origin pixel stealing attacks in the browser using SVG filters.

See also: New PoC Exploit for Sudo Chroot Privilege Escalation Vulnerability

The last category of attack combines this with Android's window blur APIto leak rendering data and allow theft from victim apps. To achieve this, a malicious Android app is used to send the victim app's pixels to the rendering pipeline and overlay semi-transparent activities using intents - an Android software mechanism that allows navigation between apps and activities.

In other words, the idea is to call a target application, containing information of interest (e.g. 2FA codes), and cause the data to be submitted for rendering. Then, the malicious application, installed on the device, isolates the coordinates of a target pixel (i.e., those containing the 2FA code) and invokes a stack of semi-transparent activities to cover, enlarge, and broadcast that pixel using the side-channel. This step is repeated for each pixel pushed into the rendering pipeline.

Researchers reported that Android is vulnerable to Pixnapping due to a combination of three factors that allow an app to:

1. Send another application's activities to the Android rendering pipeline (e.g. with intents)
2. Induce graphical operations (e.g. blurring) on ​​pixels displayed by another application's activities
3. Measure pixel color-dependent side effects of graphical operations

See also: Ivanti: Warns of 13 vulnerabilities in Endpoint Manager (EPM)

Pixnapping attack: Malicious Android apps steal 2FA passwords

Google is tracking the issue as CVE-2025-48561 (CVSS score: 5.5). Patches for the vulnerability were issued by the tech giant as part of the September 2025 Android Security Bulletin, with Google noting that: “An application that requests multiple blurs: (1) allows pixel theft by measuring how long it takes to perform a blur on windows, [and] (2) is probably not very valid anyway.”

Selecting the team

🔑 Secure your passwords with Proton Pass

Password manager from Proton — end-to-end encryption, passkeys, built-in 2FA, and monitoring for leaks of your credentials.

  • ✔ Encrypted storage of passwords & passkeys
  • ✔ Notification if any of your passwords are leaked (Dark Web Monitoring)
  • ✔ Free version — on all devices
Get your free Proton Pass →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

However, it has since been revealed that there is a workaround that can be used to re-enable Pixnapping. The company is said to be working on a fix.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr/politiki-syntaxis/
Member of the SecNews Editorial Team. Covers software vulnerabilities, data breaches, cyberattacks and technology developments. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS