• Home
  • News
    • PRESS RELEASE
  • Shop
  • BUSINESS
    • CRYPTO
    • ECONOMY
    • FINANCE
    • MARKET
    • MONEY
  • TECH
    • APPS
    • GADGET
    • MOBILE
    • SCIENCE
  • SOCIAL MEDIA
  • ENTERTAINMENT
    • ARTS & THEATER
    • GAMING
    • GAMBLING
    • MOVIE
    • MUSIC
    • SHOWS
    • SPORTS
  • LIFESTYLE
    • CELEBRITY
    • CULTURE
    • Education
    • FASHION
    • FOOD
    • HEALTH
    • HISTORY
    • Nature
    • Religion
    • Shopping
    • TRAVEL
  • REAL ESTATE
  • Blog
  • Classifieds
  • Home
  • News
    • PRESS RELEASE
  • Shop
  • BUSINESS
    • CRYPTO
    • ECONOMY
    • FINANCE
    • MARKET
    • MONEY
  • TECH
    • APPS
    • GADGET
    • MOBILE
    • SCIENCE
  • SOCIAL MEDIA
  • ENTERTAINMENT
    • ARTS & THEATER
    • GAMING
    • GAMBLING
    • MOVIE
    • MUSIC
    • SHOWS
    • SPORTS
  • LIFESTYLE
    • CELEBRITY
    • CULTURE
    • Education
    • FASHION
    • FOOD
    • HEALTH
    • HISTORY
    • Nature
    • Religion
    • Shopping
    • TRAVEL
  • REAL ESTATE
  • Blog
  • Classifieds
No Result
View All Result
No Result
View All Result
Google Pixel ‘aCropalypse’ exploit reverses edited parts of screenshots

Google Pixel ‘aCropalypse’ exploit reverses edited parts of screenshots

Utah Digital News by Utah Digital News
March 19, 2023
in TECH
0
Share on FacebookShare on Twitter


A security flaw affecting the Google Pixel’s default screenshot editing utility, Markup, allows images to become partially “unedited,” potentially revealing the personal information users chose to hide, as spotted earlier by 9to5Google and Android Police. The vulnerability, which was discovered by reverse engineers Simon Aaarons and David Buchanan, has since been patched by Google but still has widespread implications for the edited screenshots shared prior to the update.

As detailed in a thread Aaarons posted on Twitter, the aptly-named “aCropalypse” flaw makes it possible for someone to partially recover PNG screenshots edited in Markup. That includes scenarios where someone may have used the tool to crop or scribble out their name, address, credit card number, or any other kind of personal information the screenshot may contain. A bad actor could exploit this vulnerability to reverse some of those changes and obtain information users thought they had been hiding.

In a forthcoming FAQ page obtained early by 9to5Google, Aarons and Buchanan explain that this flaw exists because Markup saves the original screenshot in the same file location as the edited one, and never deletes the original version. If the edited version of the screenshot is smaller than the original, “the trailing portion of the original file is left behind, after the new file is supposed to have ended.”

According to Buchanan, this bug first emerged about five years ago, around the same time Google introduced Markup with the Android 9 Pie update. That’s what makes this all the worse, as years-worth of older screenshots edited with Markup and shared on social media platforms could be vulnerable to the exploit.

The FAQ page states that while certain sites, including Twitter, re-process the images posted on the platforms and strip them of the flaw, others, such as Discord, don’t. Discord only just patched the exploit in a recent January 17th update, which means edited images shared to the platform before that date may be at risk. It’s still not clear whether there are any other affected sites or apps and if so, which ones they are.

The example posted by Aarons (embedded above) shows a cropped image of a credit card posted to Discord, which also has the card number blocked out using the Markup tool’s black pen. Once Aarons downloads the image and exploits the aCropalypse vulnerability, the top part of the image becomes corrupted, but he can still see the pieces that were edited out in Markup, including the credit card number. You can read more about the technical details of the flaw in Buchanan’s blog post.

After Aarons and Buchanan reported the flaw (CVE-2023-21036) to Google in January, the company patched the issue in a March security update for the Pixel 4A, 5A, 7, and 7 Pro with its severity classified as “high.” It’s unclear when this update will arrive for the other devices affected by the vulnerability, and Google didn’t immediately respond to The Verge’s request for more information. If you want to see how the issue works for yourself, you can upload a screenshot edited with a non-updated version of the Markup tool to this demo page created by Aarons and Buchanan. Or, you can check out some of the scary examples posted on the web.

This flaw came to light just days after Google’s security team found that the Samsung Exynos modems included in the Pixel 6, Pixel 7, and select Galaxy S22 and A53 models could allow hackers to “remotely compromise” devices using just a victim’s phone number. Google has since patched the issue in its March update, although this still isn’t available for the Pixel 6, 6 Pro, and 6A devices yet.





Source link

You might also like

OpenAI unleashes GPT-4, SVB files for bankruptcy, and a PE firm acquires Pornhub

OpenAI unleashes GPT-4, SVB files for bankruptcy, and a PE firm acquires Pornhub

March 19, 2023
FBI takes down Hive ransomware network

Two hackers charged with last year’s DEA portal breach

March 18, 2023
Utah Digital News

Utah Digital News

Related Stories

OpenAI unleashes GPT-4, SVB files for bankruptcy, and a PE firm acquires Pornhub

OpenAI unleashes GPT-4, SVB files for bankruptcy, and a PE firm acquires Pornhub

by Utah Digital News
March 19, 2023
0

Welcome to Week in Review, folks, TechCrunch’s regular recap of the week in tech. GPT-4, OpenAI’s text- and image-understanding AI,...

FBI takes down Hive ransomware network

Two hackers charged with last year’s DEA portal breach

by Utah Digital News
March 18, 2023
0

Two men have been charged for their alleged roles in last year’s hack of the Drug Enforcement Agency’s web portal,...

How to pitch me: 7 investors discuss what they’re looking for in March 2023

How to pitch me: 7 investors discuss what they’re looking for in March 2023

by Utah Digital News
March 16, 2023
0

Walter Thompson Contributor Editorial Manager Walter Thompson edits staff and guest articles for TechCrunch+ and manages TechCrunch's guest contributor program....

Samsung’s Galaxy A54 and A34 phones get a Galaxy S23-inspired facelift

Samsung’s Galaxy A54 and A34 phones get a Galaxy S23-inspired facelift

by Utah Digital News
March 15, 2023
0

Samsung’s Galaxy A34 and A54 are the latest additions to its popular midrange A-series. Although both phones offer a number...

Next Post
Credit Suisse sold in cut-price deal to avert banking crisis

Credit Suisse sold in cut-price deal to avert banking crisis

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

utahdigitalnews.com

  • Disclaimer
  • Privacy Policy
  • Copyright Notice
  • Anti Spam Policy
  • Medical Disclaimer
  • DMCA Compliance
  • Terms and Conditions
  • Social Media Disclaimer
  • Amazon Affiliate disclaimer

© 2022 utahdigitalnews.com

No Result
View All Result
  • Home
  • News
    • PRESS RELEASE
  • Shop
  • BUSINESS
    • CRYPTO
    • ECONOMY
    • FINANCE
    • MARKET
    • MONEY
  • TECH
    • APPS
    • GADGET
    • MOBILE
    • SCIENCE
  • SOCIAL MEDIA
  • ENTERTAINMENT
    • ARTS & THEATER
    • GAMING
    • GAMBLING
    • MOVIE
    • MUSIC
    • SHOWS
    • SPORTS
  • LIFESTYLE
    • CELEBRITY
    • CULTURE
    • Education
    • FASHION
    • FOOD
    • HEALTH
    • HISTORY
    • Nature
    • Religion
    • Shopping
    • TRAVEL
  • REAL ESTATE
  • Blog
  • Classifieds

© 2022 utahdigitalnews.com