Tuesday, October 21, 2025
  • Login
Euro Times
No Result
View All Result
  • Home
  • Finance
  • Business
  • World
  • Politics
  • Markets
  • Stock Market
  • Cryptocurrency
  • Investing
  • Health
  • Technology
  • Home
  • Finance
  • Business
  • World
  • Politics
  • Markets
  • Stock Market
  • Cryptocurrency
  • Investing
  • Health
  • Technology
Euro Times
No Result
View All Result

Google Pixel vulnerability allows bad actors to undo Markup screenshot edits and redactions

by Igor Bonifacic
March 19, 2023
in Technology
Reading Time: 2 mins read
A A
0
Home Technology
Share on FacebookShare on Twitter


When Google began rolling out Android’s , the company addressed a “High” severity vulnerability involving the Pixel’s Markup screenshot tool. Over the weekend, and , the reverse engineers who discovered CVE-2023-21036, shared more information about the security flaw, revealing Pixel users are still at risk of their older images being compromised due to the nature of Google’s oversight.

In short, the “aCropalypse” flaw allowed someone to take a PNG screenshot cropped in Markup and undo at least some of the edits in the image. It’s easy to imagine scenarios where a bad actor could abuse that capability. For instance, if a Pixel owner used Markup to redact an image that included sensitive information about themselves, someone could exploit the flaw to reveal that information. You can find the technical details on .

Introducing acropalypse: a serious privacy vulnerability in the Google Pixel’s inbuilt screenshot editing tool, Markup, enabling partial recovery of the original, unedited image data of a cropped and/or redacted screenshot. Huge thanks to @David3141593 for his help throughout! pic.twitter.com/BXNQomnHbr

— Simon Aarons (@ItsSimonTime) March 17, 2023

According to Buchanan, the flaw has existed for about five years, coinciding with the release of Markup alongside . And therein lies the problem. While March’s security patch will prevent Markup from compromising future images, some screenshots Pixel users may have shared in the past are still at risk.

It’s hard to say how concerned Pixel users should be about the flaw. According to a forthcoming Aarons and Buchanan shared with and , some websites, including Twitter, process images in such a way that someone could not exploit the vulnerability to reverse edit a screenshot or image. Users on other platforms aren’t so lucky. Aarons and Buchanan specifically identify Discord, noting the chat app did not patch out the exploit until its recent January 17th update. At the moment, it’s unclear if images shared on other social media and chat apps were left similarly vulnerable.

Google did not immediately respond to Engadget’s request for comment and more information. The March security update is currently available on the Pixel 4a, 5a, 7 and 7 Pro, meaning Markup can still produce vulnerable images on some Pixel devices. It’s unclear when Google will push the patch to other Pixel devices. If you own a Pixel phone without the patch, avoid using Markup to share sensitive images.





Source link

Tags: actorsbadEditsGoogleMarkupPixelredactionsscreenshotUndovulnerability
Previous Post

Money in bank: Women’s share in deposits rises, but gender gap in average holding widens

Next Post

Today’s the last day to switch away from Twitter’s SMS 2FA method

Related Posts

Google confirms when Android 16 QPR2 Beta 3 will return (Update: It’s back)

Google confirms when Android 16 QPR2 Beta 3 will return (Update: It’s back)

by Ryan McNeal
October 20, 2025
0

Mishaal Rahman / Android AuthorityTL;DR Google just lately halted the roll out of Android 16 QPR2 Beta 3 because of...

A massive Amazon server outage took down Fortnite, Alexa, Snapchat, and more

A massive Amazon server outage took down Fortnite, Alexa, Snapchat, and more

by Jess Weatherbed
October 20, 2025
0

A serious Amazon Net Companies (AWS) outage took down a number of on-line companies for a number of hours this...

The best smartphones to buy in 2025

The best smartphones to buy in 2025

by Cherlynn Low,Sam Rutherford
October 20, 2025
0

You may have already got a good suggestion of which smartphone you need to be your subsequent one. However there...

X is testing a new way of opening links without fully covering an X post, allowing users to see the Like, Repost, and other buttons, starting on iOS (Cheyenne MacDonald/Engadget)

X is testing a new way of opening links without fully covering an X post, allowing users to see the Like, Repost, and other buttons, starting on iOS (Cheyenne MacDonald/Engadget)

by Euro Times
October 19, 2025
0

Cheyenne MacDonald / Engadget: X is testing a brand new approach of opening hyperlinks with out totally protecting an X...

Kohler unveils a camera for your toilet

Kohler unveils a camera for your toilet

by Anthony Ha
October 20, 2025
0

Dwelling items firm Kohler just lately unveiled a brand new gadget known as the Dekoda — a $599 digicam that...

I found a cheap Windows laptop that I’d actually use for work travel – and it’s on sale

I found a cheap Windows laptop that I’d actually use for work travel – and it’s on sale

by Kyle Kucharski
October 19, 2025
0

ZDNET's key takeaways The Acer Aspire Go 15 is obtainable for round $299 throughout main retailers. For an reasonably priced...

Next Post
Today’s the last day to switch away from Twitter’s SMS 2FA method

Today’s the last day to switch away from Twitter’s SMS 2FA method

DNA Data Storage: A Solution Looking for a Problem?

DNA Data Storage: A Solution Looking for a Problem?

Oil Falls As Traders Focus On Surplus And US-China Trade Talks

Oil Falls As Traders Focus On Surplus And US-China Trade Talks

October 21, 2025
Calgro M3 Holdings Limited 2026 Q2 – Results – Earnings Call Presentation (OTCMKTS:CLMHF) 2025-10-20

Calgro M3 Holdings Limited 2026 Q2 – Results – Earnings Call Presentation (OTCMKTS:CLMHF) 2025-10-20

October 20, 2025
Google confirms when Android 16 QPR2 Beta 3 will return (Update: It’s back)

Google confirms when Android 16 QPR2 Beta 3 will return (Update: It’s back)

October 20, 2025
What was stolen in the Louvre heist? What to know about the 8 jewelry pieces — and the ‘race against time’ to save them.

What was stolen in the Louvre heist? What to know about the 8 jewelry pieces — and the ‘race against time’ to save them.

October 21, 2025
MSNBC Struggles to Find Illegality with Government Stretching Dollars

MSNBC Struggles to Find Illegality with Government Stretching Dollars

October 21, 2025
Democrats Move To Cut Off Funding For Trump’s White House Ballroom

Democrats Move To Cut Off Funding For Trump’s White House Ballroom

October 20, 2025
Euro Times

Get the latest news and follow the coverage of Business & Financial News, Stock Market Updates, Analysis, and more from the trusted sources.

CATEGORIES

  • Business
  • Cryptocurrency
  • Finance
  • Health
  • Investing
  • Markets
  • Politics
  • Stock Market
  • Technology
  • Uncategorized
  • World

LATEST UPDATES

Oil Falls As Traders Focus On Surplus And US-China Trade Talks

Calgro M3 Holdings Limited 2026 Q2 – Results – Earnings Call Presentation (OTCMKTS:CLMHF) 2025-10-20

  • Disclaimer
  • Privacy Policy
  • DMCA
  • Cookie Privacy Policy
  • Terms and Conditions
  • Contact us

Copyright © 2022 - Euro Times.
Euro Times is not responsible for the content of external sites.

No Result
View All Result
  • Home
  • Finance
  • Business
  • World
  • Politics
  • Markets
  • Stock Market
  • Cryptocurrency
  • Investing
  • Health
  • Technology

Copyright © 2022 - Euro Times.
Euro Times is not responsible for the content of external sites.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In