Close Menu
Tech Nova Mindset – Empower Innovation and Forward Thinking

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    AI Hacks Are Bad. AI Worms and Viruses Will Be Worse

    August 6, 2026

    OpenAI’s Browser Could Be Hijacked to Spam Your WhatsApp Contacts

    August 6, 2026

    OpenAI Didn’t Notice Its AI Agents Using a Message Board to Plan Their Hacking Spree

    August 6, 2026
    Facebook X (Twitter) Instagram
    Trending
    • AI Hacks Are Bad. AI Worms and Viruses Will Be Worse
    • OpenAI’s Browser Could Be Hijacked to Spam Your WhatsApp Contacts
    • OpenAI Didn’t Notice Its AI Agents Using a Message Board to Plan Their Hacking Spree
    • IEEE Course on Using AI to Modernize Power Grids
    • The Most Dangerous AI Hacking Techniques Still Have Humans in the Loop
    • Puzzle Corner | MIT Technology Review
    • AI Influencers Are Heading Into Uncharted Territory
    • The Download: NASA’s new telescope and Chinese tech import curbs
    Tech Nova Mindset – Empower Innovation and Forward Thinking
    • Home
    • Gadgets
    • Reviews
    • Tech News
    • Future Tech
    • AI & Robotics
    • How-To Guides
    • More
      • Cybersecurity
      • Startups & Innovation
    Tech Nova Mindset – Empower Innovation and Forward Thinking
    Home»Tech News»This new Android exploit can steal everything on your screen – even 2FA codes
    Tech News

    This new Android exploit can steal everything on your screen – even 2FA codes

    kirklandc008@gmail.comBy kirklandc008@gmail.comOctober 14, 2025No Comments4 Mins Read
    Facebook Twitter Pinterest LinkedIn Tumblr Email
    This new Android exploit can steal everything on your screen - even 2FA codes
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Elyse Betters Picaro / ZDNET

    Follow ZDNET: Add us as a preferred source on Google.

    ZDNET’s key takeaways

    • Pixnapping could be used to steal private data, including 2FA codes.
    • Side-channel attack abuses Google Android APIs to steal data on display.
    • Flaw is partially patched, although a more complete fix is due in December.

    A new attack method demonstrated by researchers could lead to the theft of two-factor authentication (2FA) codes and more on Android devices.

    Also: This fundamental Android feature is ‘absolutely not’ going away, says Google – but it is changing

    The attack technique, detailed in a paper titled Pixnapping: Bringing Pixel Stealing out of the Stone Age (PDF), has been developed by researchers from the University of California, Berkeley, San Diego, Washington, and Carnegie Mellon.

    Dubbed “Pixnapping,” this attack vector begins when a victim unknowingly installs a malicious mobile application on their Android smartphone.

    Notably, the app doesn’t need to abuse permissions to perform this attack, which exploits existing Android APIs, pixel rendering, and a hardware side channel.

    The steps

    There are three steps to Pixnapping, so-called due to its abuse of pixels rendered by a target app, such as Google Authenticator. The first stage requires the malicious app to invoke a target app and make a system call to prompt the submission of sensitive data to the Android rendering pipeline.

    Also: Your Android phone’s most powerful security feature is off by default and hidden – turn it on now

    In the second stage, this app will then induce graphical operations (blurring) by launching a “semi-transparent” layer on individual sensitive pixels rendered by the target app — such as the part of a screen when an authentication app renders 2FA characters. Masking is then used to isolate, enlarge, and determine the graphical nature of the pixels.

    The third and final stage requires the abuse of a side channel, GPU.Zip, to steal the pixels on display, one by one. In other words, the malicious app is taking pixels to capture a form of “screenshot” of content it should not have access to.

    What are the consequences?

    This attack could lead to the theft of visible information, such as private messages, 2FA codes, open email content, and more.

    Regarding 2FA, experiments to leak 100 of them within the required 30-second window were successful on Google Pixel phones, but there were varying degrees of success in grabbing the full six digits within Google Authenticator. However, this was not successful on a Samsung Galaxy S25 “due to significant noise.”

    Also: This silent Android feature scans your photos for ‘sensitive content’ – how to disable it

    “We have demonstrated Pixnapping attacks on Google and Samsung phones and end-to-end recovery of sensitive data from websites, including Gmail and Google Accounts, and apps, including Signal, Google Authenticator, Venmo, and Google Maps,” the researchers say. “Notably, our attack against Google Authenticator allows any malicious app to steal 2FA codes in under 30 seconds while hiding the attack from the user.”

    Pixnapping was performed on five devices running Android versions 13 to 16: the Google Pixel 6, Google Pixel 7, Google Pixel 8, Google Pixel 9, and Samsung Galaxy S25. However, it is possible that Pixnapping could impact other handsets, as the team says the “core mechanisms enabling the attack are typically available in all Android devices.”

    Is this security flaw patched?

    The security flaw has been assigned the tracker CVE-2025-48561. A patch has been issued (1, 2). The team says that this patch mitigates Pixnapping “by limiting the number of activities an app can invoke blur on,” but also says a workaround exists, and this has been privately disclosed to Google.

    Also: How to turn on Android’s Private DNS mode – and why you should ASAP

    It is not known if this exploit is being used in the wild, although Google told The Register there is no evidence of active campaigns. In addition, this partial mitigation will be followed by an additional patch in the tech giant’s December Android security bulletin.

    Get the morning’s top stories in your inbox each day with our Tech Today newsletter.

    2FA Android codes exploit screen steal
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    kirklandc008@gmail.com
    • Website

    Related Posts

    Hackers hijack hotel Wi-Fi DNS to steal Microsoft 365 accounts

    July 25, 2026

    Russian hackers exploit unpatched Zimbra servers to steal emails

    July 24, 2026

    Did Chinese AI Steal From Anthropic, and OpenAI Loses Control of Two Models

    July 24, 2026
    Leave A Reply Cancel Reply

    Top Posts

    Nothing CEO says phone prices are going to keep going up

    June 12, 20267 Views

    Google DeepMind Plans to Track AGI Progress With These 10 Traits of General Intelligence

    March 21, 20263 Views

    The AirPods 4 and Lego’s brick-ified Grogu are our favorite deals this week

    October 12, 20253 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Latest Reviews

    Subscribe to Updates

    Get the latest tech news from FooBar about tech, design and biz.

    Recent Posts
    • AI Hacks Are Bad. AI Worms and Viruses Will Be Worse
    • OpenAI’s Browser Could Be Hijacked to Spam Your WhatsApp Contacts
    • OpenAI Didn’t Notice Its AI Agents Using a Message Board to Plan Their Hacking Spree
    • IEEE Course on Using AI to Modernize Power Grids
    • The Most Dangerous AI Hacking Techniques Still Have Humans in the Loop

    AI Hacks Are Bad. AI Worms and Viruses Will Be Worse

    August 6, 2026

    OpenAI’s Browser Could Be Hijacked to Spam Your WhatsApp Contacts

    August 6, 2026

    OpenAI Didn’t Notice Its AI Agents Using a Message Board to Plan Their Hacking Spree

    August 6, 2026

    IEEE Course on Using AI to Modernize Power Grids

    August 5, 2026
    Facebook X (Twitter) Instagram Pinterest
    • About Us
    • Contact Us
    • Privacy Policy
    • Terms and Conditions
    • Disclaimer
    © 2026 TechNovaMindset. Designed by By Pro.

    Type above and press Enter to search. Press Esc to cancel.