Most Viewed Content:

India’s censorship body gave power to remove pirated Movies from platforms

India’s Ministry of Information and Broadcasting announced that its...

Microsoft working on new features for Win11 / Win12: smart notifications, depth-of-field effects

According to the source Albacore (@thebookisclosed), Microsoft is preparing...

OpenAI Launched Assistants API, Allowing Developers to Customize AI Assistants with One Click

At today's OpenAI's first developer conference, OpenAI launched the...

Google Pixel phone screenshot editing tool is exposed to security vulnerabilities

Google’s Pixel phone comes with a screenshot editing tool called Markup that has been exposed to a security flaw that could cause users’ edited screenshots to be partially restored, exposing private information that users want to hide. The vulnerability was first revealed by reverse engineers Simon Aaarons and David Buchanan, and Google has fixed the vulnerability in a security update in March, but screenshots shared online by users before the update are still at risk.

According to a Twitter post by Aaarons, the vulnerability, known as “aCropalypse,” could allow partial restoration of PNG-formatted screenshots edited with Markup, such as when users use the tool to crop or smear their name, address, credit card number or other private information. Any private information could be reverted, which could be used to obtain private information that the user thought was hidden from view.

Aaarons and Buchanan explained that the vulnerability exists because Markup saves the original screenshot in the same file location as the edited screenshot and never removes the original version.

According to Buchanan, the vulnerability first appeared about five years ago, around the same time Google introduced Markup in its Android 9 Pie update, making the situation even worse because old screenshots edited with Markup and shared on social media platforms could be at risk.

While some sites (including Twitter) will reprocess images uploaded to the platform and remove the vulnerability, others (such as Discord) do not. It is unclear if there are other affected sites or apps.

An example posted by Aaarons (above) shows an edited image of a credit card with the card number obscured with the Markup tool’s black pen. When Aaarons downloaded the image and processed it using the aCropalypse vulnerability, the top of the image became corrupted, but he could still see the edited parts in Markup, including the credit card number.

Google has fixed the vulnerability in a March security update, categorizing its severity as “high.” The update is currently available for models like the Pixel 4a, 5a, 7, and 7 Pro, meaning Markup may still produce vulnerable images on some Pixel devices. It’s unclear when Google will push this patch to other Pixel devices.

Latest

Tesla releases new Model 3 Performance: Equipped with fourth-generation drive unit

Tesla today released the new Model 3 Performance, which...

Elon Musk hints Tesla self-driving taxis will be called ‘Cybercab’, launching in August

Tesla CEO Elon Musk recently announced that Tesla’s self-driving...

Google Android 15: Restricts sideloaded apps from obtaining sensitive permissions

Foreign technology media Android Authority recently excavated the latest...

Mercedes-Benz G 580 off-road EV officially released

Mercedes-Benz today released a new pure electric G-Class off-road...

Newsletter

Don't miss

Tesla releases new Model 3 Performance: Equipped with fourth-generation drive unit

Tesla today released the new Model 3 Performance, which...

Elon Musk hints Tesla self-driving taxis will be called ‘Cybercab’, launching in August

Tesla CEO Elon Musk recently announced that Tesla’s self-driving...

Google Android 15: Restricts sideloaded apps from obtaining sensitive permissions

Foreign technology media Android Authority recently excavated the latest...

Mercedes-Benz G 580 off-road EV officially released

Mercedes-Benz today released a new pure electric G-Class off-road...

Chery iCAR 03T preview image released, will debut at Beijing Auto Show

Today Chery Automobile officially released a preview image of...
Stephen Cruise
Stephen Cruisehttps://www.techgoing.com
Stephen Cruise is a senior editor covering latest smartphones, EVs, PC gaming, console, and tech with 11 years of experience.

New Citroen C3 Aircross to be unveiled on April 18

Recently, according to overseas media reports, the new Citroen C3 AIRCROSS will be unveiled on April 18. The new car is internally codenamed CC24...

Nubia announced Z60 Ultra photographer’s edition phone for global markets

Nubia officially announced this week that its Z60 Ultra photography version of the phone will be launched in the global market. The price varies...

Vivo T3x phone launched in India with 6000mAh battery, starting from INR 12,499

The Vivo T3x phone was officially released in India today. It is equipped with a Snapdragon 6 Gen 1 processor and a 6000mAh battery....