Android Vulnerability ‘Pixnapping’ Allows Malicious Apps to Access 2FA Codes via Pixel-Stealing
A newly discovered Android vulnerability, dubbed Pixnapping, allows malicious apps to steal two-factor authentication (2FA) codes, Google Maps timeline data, and other sensitive information without requesting any special permissions. Researchers from the University of California (Berkeley and San Diego), University of Washington, and Carnegie Mellon University identified this side-channel attack, which exploits Android APIs and a GPU hardware side-channel to capture pixel-by-pixel data from victim apps. The attack uses semi-transparent overlay activities and the Android window blur API to extract rendering data, effectively bypassing standard security mitigations. Tests were conducted on several Google and Samsung devices running Android versions 13 to 16, though other Android devices may also be vulnerable. Google assigned CVE-2025-48561 to this issue, issuing partial patches in September 2025 and planning a comprehensive fix in December. While exploitation requires specific device data and user installation of a malicious app, no in-the-wild attacks have been reported so far. The research also highlights a method for attackers to detect installed apps, bypassing restrictions introduced in Android 11, which remains unpatched. Experts recommend sensitive apps adopt measures to opt out and restrict pixel measurement to mitigate potential attacks.
