All Topics
All Topics
Technology
Technology
Design
Design
Programming
Programming
Science
Science
News
News
Gaming
Gaming
Entertainment
Entertainment
Business
Business
Finance
Finance
Sports
Sports
Health
Health
Food
Food
Travel
Travel
Art
Art
Music
Music
Books
Books
Education
Education
Politics
Politics
Personal
Personal
No algorithm. No AI slop. No ads. Just RSS. Pro-human. Indie writers. Real journalism. Open web. Chronological. Hand toasted.

Pixnapping: New Android Security Attack Steals Data from Apps and Websites

By

kevcampb

7mo ago· 6 min readenNews

Summary

Pixnapping is a new class of Android security attacks that enables malicious apps to stealthily leak information from other apps and websites. The attack exploits Android APIs and a hardware side channel affecting nearly all modern Android devices. Researchers demonstrated successful attacks on Google and Samsung phones, recovering sensitive data from Gmail, Google Accounts, Signal, Google Authenticator, Venmo, and Google Maps. Notably, the attack can steal 2FA codes from Google Authenticator in under 30 seconds while remaining hidden from users.

Key quotes

· 4 pulled
Pixnapping is a new class of attacks that allows a malicious Android app to stealthily leak information displayed by other Android apps or arbitrary websites.
Pixnapping exploits Android APIs and a hardware side channel that affects nearly all modern Android devices.
We have demonstrated Pixnapping attacks on Google and Samsung phones and end-to-end recovery of sensitive data from websites including Gmail and Google Accounts and apps including Signal, Google Authenticator, Venmo, and Google Maps.
Notably, our attack against Google Authenticator allows any malicious app to steal 2FA codes in under 30 seconds while hiding the attack from the user.
Snippet from the RSS feed
Pixnapping is a new class of attacks that allows a malicious Android app to stealthily leak information displayed by other Android apps or arbitrary websites. Pixnapping exploits Android APIs and a hardware side channel that affects nearly all modern Andr

You might also wanna read