Google Pixel vulnerability allows bad actors to undo Markup screenshot edits and redactions


When Google began rolling out Android’s , the company addressed a “High” severity vulnerability involving the Pixel’s Markup screenshot tool. Over the weekend, and , the reverse engineers who discovered CVE-2023-21036, shared more information about the security flaw, revealing Pixel users are still at risk of their older images being compromised due to the nature of Google’s oversight.

In short, the “aCropalypse” flaw allowed someone to take a PNG screenshot cropped in Markup and undo at least some of the edits in the image. It’s easy to imagine scenarios where a bad actor could abuse that capability. For instance, if a Pixel owner used Markup to redact an image that included sensitive information about themselves, someone could exploit the flaw to reveal that information. You can find the technical details on .

According to Buchanan, the flaw has existed for about five years, coinciding with the release of Markup alongside . And therein lies the problem. While March’s security patch will prevent Markup from compromising future images, some screenshots Pixel users may have shared in the past are still at risk.

It’s hard to say how concerned Pixel users should be about the flaw. According to a forthcoming Aarons and Buchanan shared with and , some websites, including Twitter, process images in such a way that someone could not exploit the vulnerability to reverse edit a screenshot or image. Users on other platforms aren’t so lucky. Aarons and Buchanan specifically identify Discord, noting the chat app did not patch out the exploit until its recent January 17th update. At the moment, it’s unclear if images shared on other social media and chat apps were left similarly vulnerable.

Google did not immediately respond to Engadget’s request for comment and more information. The March security update is currently available on the Pixel 4a, 5a, 7 and 7 Pro, meaning Markup can still produce vulnerable images on some Pixel devices. It’s unclear when Google will push the patch to other Pixel devices. If you own a Pixel phone without the patch, avoid using Markup to share sensitive images.





Source link: https://www.engadget.com/google-pixel-vulnerability-allows-bad-actors-to-undo-markup-screenshot-edits-and-redactions-195322267.html?src=rss

Sponsors

spot_img

Latest

XRP Tops List Of Gainers As Whale Interest Spikes

XRP has been on the front lines of crypto news for the past couple of weeks as Ripple’s lawsuit with the Securities and...

How Ultra Micro Holding Connects Finance to Millions in Indonesia

Microfinancing offers an indispensable lifeline to entrepreneurs around the...

Liverpool target midfield additions amid Jude Bellingham and Enzo Fernandez links but reliable source says further January business is unlikely

Liverpool have been dealt a transfer blow with the news that they’re unlikely to make any further signings in the January window. The Reds...

Wout Weghorst has another shocker

Manchester United have qualified for the last 16 of the Europa League, beating Barcelona 4-3 on aggregate after a 2-1 win in the...

Pay-per-view price, TV channel and live stream as ‘Money’ makes London fight debut in exhibition bout against Geordie Shore star

Floyd Mayweather’s latest exhibition venture will take place in the UK tonight against reality TV star Aaron Chalmers. The 50-0 legend, who has never...