BLOCK PATRIOT
  • Home
  • Cryptocurrency
  • Bitcoin
  • Ethereum
  • Blockchain
  • Altcoin
  • Metaverse
  • Web 3.0
  • DeFi
No Result
View All Result
BLOCK PATRIOT
No Result
View All Result
Home Business

Security Hole Found in Google Pixel Devices: Redacted Photos Recovered

by Caio Rodrigues
March 23, 2023
in Business
0
Security Hole Found in Google Pixel Devices: Redacted Photos Recovered
152
SHARES
1.9k
VIEWS
Share on FacebookShare on Twitter

A dangerous security hole has been discovered in the default screenshot editing application on Google’s flagship smartphone, Google Pixel.

The editing utility called ‘Markup’ allows images to become partially “unedited,” which may reveal details the sender wanted to hide.

“Introducing acropalypse: a serious privacy vulnerability in the Google Pixel’s inbuilt screenshot editing tool, Markup, enabling partial recovery of the original, unedited image data of a cropped and/or redacted screenshot,” tweeted Simon Aaarons, the reverse engineer who discovered the vulnerability along with David Buchanan.

Although Google has fixed the vulnerability, its impact is still far-reaching, particularly for the edited screenshots that were shared before the update.

According to Aaarons’ Twitter thread, a vulnerability known as the “acropalypse” flaw can partially recover edited PNG screenshots in Markup. This poses a risk for users who may have used the tool to crop or scribble out sensitive information, such as their personal details or credit card number, as a malicious actor could exploit the flaw to reverse the changes and obtain the hidden information.

According to Aarons and Buchanan, the flaw is due to Markup’s behavior of storing the original screenshot in the same file location as the edited one, without deleting the original version. As explained, if the edited version of the screenshot has a smaller file size than the original, “the trailing portion of the original file is left behind, after the new file is supposed to have ended.”

“This bug is a bad one. You can patch it, but you can’t easily un-share all the vulnerable images you may have sent. The bug existed for about 5 years before being patched, which is mind-blowing given how easy it is to spot when you look closely at an output file,” wrote Buchanan.

iPhone has a feature to remove Medadata

The problem only exists in the Google Pixel devices, whereas Apple’s iPhone has the feature to share files with or without metadata.

iPhones provide three options: “save without metadata, share without metadata, and share with metadata.”

Although some websites like Twitter re-process the images uploaded on their platforms to remove the flaw, others like Discord do not. Discord only addressed the vulnerability with a recent update released on January 17th, meaning any edited images shared before that date may still be at risk.

It remains uncertain whether there are any other sites or applications that are affected by the flaw. Buchanan has explained this issue with technical details in a blog post.

“IMHO, the takeaway here is that API footguns should be treated as security vulnerabilities,” wrote Buchanan.

The discovery of this flaw occurred shortly after Google’s security team uncovered a vulnerability in the Samsung Exynos modems found in devices like the Pixel 6, Pixel 7, and specific models of the Galaxy S22 and A53.

The security flaw could enable hackers to remotely compromise devices using just the phone number of the victim. Google has released a patch for this issue in its March update, but the update is not yet available for the Pixel 6, 6 Pro, and 6A devices.


This article is originally from MetaNews.

  • Trending
  • Comments
  • Latest
$CHUNKS STEALTH LAUNCH

$CHUNKS STEALTH LAUNCH

April 29, 2023
Dogecoin and Shiba Inu Rival That Was Just Listed on Binance.US Sees 70% of Its Holders Sitting on Losses

Dogecoin and Shiba Inu Rival That Was Just Listed on Binance.US Sees 70% of Its Holders Sitting on Losses

April 27, 2023
Leading Gaming Token FUN Token Partners With DWF Labs

Leading Gaming Token FUN Token Partners With DWF Labs

April 27, 2023
The latest BTC crash has everyone in the market speculating ‘why’

The latest BTC crash has everyone in the market speculating ‘why’

April 27, 2023
Bitcoin [BTC]: Short products for the win as investors shy away from long positions

Bitcoin [BTC]: Short products for the win as investors shy away from long positions

0
24 Crypto Terms You Should Know

24 Crypto Terms You Should Know

0
Can bitcoin hedge inflation, and other questions to which the answer is no

Can bitcoin hedge inflation, and other questions to which the answer is no

0
Shopify Launches Comprehensive Blockchain Suite For Merchants

Shopify Launches Comprehensive Blockchain Suite For Merchants

0
Trader Issues Warning on Ethereum-Based Altcoin That’s Soared Over 300% in a Month, Updates Outlook on Bitcoin

Trader Issues Warning on Ethereum-Based Altcoin That’s Soared Over 300% in a Month, Updates Outlook on Bitcoin

September 21, 2023
Bitcoin Maintains Price Above $27,000 as Predictions from Stakeholders Come In Bullish and Bearish

Bitcoin Maintains Price Above $27,000 as Predictions from Stakeholders Come In Bullish and Bearish

September 21, 2023
Justin Sun’s High-Yield Project Is Set to Eclipse Huobi Global

Justin Sun’s High-Yield Project Is Set to Eclipse Huobi Global

September 21, 2023

FTX sues Sam Bankman-Fried’s parents over ‘misappropriated funds’

September 21, 2023

Converter

Cryptocurrency Prices 

Categories

  • Altcoin
  • Altcoin News
  • Altcoins
  • Artificial Intelligence
  • Bitcoin
  • Blockchain
  • Blockchain Games
  • Business
  • Crypto
  • Cryptocurrencies
  • Cryptocurrency
  • Culture
  • DeFi
  • Economy
  • Education
  • Entertainment
  • Ethereum
  • Featured
  • Gambling
  • Governance
  • Health
  • Lifestyle
  • Market
  • Metaverse
  • News
  • Uncategorized
  • Web 3.0

Recent News

Trader Issues Warning on Ethereum-Based Altcoin That’s Soared Over 300% in a Month, Updates Outlook on Bitcoin

Trader Issues Warning on Ethereum-Based Altcoin That’s Soared Over 300% in a Month, Updates Outlook on Bitcoin

September 21, 2023
Bitcoin Maintains Price Above $27,000 as Predictions from Stakeholders Come In Bullish and Bearish

Bitcoin Maintains Price Above $27,000 as Predictions from Stakeholders Come In Bullish and Bearish

September 21, 2023
Justin Sun’s High-Yield Project Is Set to Eclipse Huobi Global

Justin Sun’s High-Yield Project Is Set to Eclipse Huobi Global

September 21, 2023

© 2023 BLOCK PATRIOT | All Rights Reserved

No Result
View All Result
  • Home
  • Cryptocurrency
  • Bitcoin
  • Ethereum
  • Blockchain
  • Altcoin
  • Metaverse
  • Web 3.0
  • DeFi

© 2023 BLOCK PATRIOT | All Rights Reserved