All of your photo cropping could be undone by hackers using this Google Pixel flaw

Share This Post

It specifically concerns the markup feature, which allows users to edit photos in a way that removes sensitive information from images, such as credit cards, by cropping certain aspects or applying image layers. images for elements.

Although Google released a patch for CVE-2023-21036 in its March update, the high-risk vulnerability allowed hackers to roll back many of the changes made to images on Pixel devices.

According to reverse engineers Simon Aarons and David Buchanan, who discovered the problem, with a modified – and seemingly safe – image, the bad guys can in some cases undo the mistakes. This modification exposes sensitive information in a vulnerability called “acropalypse”.

While many of us prefer to share images over channels that prefer some or all of their metadata, such as Discord, this has proven to be less secure, exposing vulnerabilities. It’s worth mentioning that Discord fixed the issue mid-January 2023. In contrast, platforms like Twitter handle images in a different way, making edits irreversible.

The vulnerability stems from Android 9 Pie that coincides with the Pixel 3 series, meaning that the 4, 5, 6, and 7 series will eventually be affected as well.

Given the age of some devices, only Pixel 4a and later are currently receiving security updates, leaving some previous models, including the 4 and any before that, without official support. still vulnerable to attack.

Additionally, edited screenshots sent before the updates were rolled out are still vulnerable and will therefore be removed where possible.

Read More:

Partnership Between Mitsubishi Electric and Nozomi Networks Strengthens Operational Technology Security Business

Mitsubishi Electric and Nozomi Networks Partnership Mitsubishi Electric and Nozomi...

Solidion Technology Inc. Completes $3.85 Million Private Placement Transaction

**Summary:** 1. Solidion TechnologyInc. has announced a private placement deal...

Analyzing the Effects of the EU’s AI Act on Tech Companies in the UK

Breaking Down the Impact of the EU’s AI Act...

Tech in Agriculture: Roundtable Discusses Innovations on the Ranch

Summary of Tech on the Ranch Roundtable Discussion: ...

Are SMEs Prioritizing Tech Investments Over Security Measures?

SMEs Dive Into Tech Investments, But Are...

Spotify Introduces Music Videos for Premium Members in Chosen Markets

3 Summaries of Spotify Unveils Music Videos for Premium...

Shearwater to Monitor Production at Equinor’s Two Oil Platforms

Shearwater GeoServices secures 4D monitoring projects from Equinor for...

Regaining Europe’s Competitive Edge in Innovation: Addressing the Innovation Lag

Europe’s Innovation Lag: How Can We Regain Our Competitive...

Related Posts

Government Warns of AI-Generated Content: Learn More about the Issue

Government issued an advisory on AI-generated content. All AI-generated content...

Africa Faces Internet Crisis: Extensive Outage Expected to Last for Months, Hardest-Hit Nations Identified

Africa’s Internet Crisis: Massive Outage Could Last Months, These...

FTC Investigates Reddit for AI Content Licensing Practices

FTC is investigating Reddit's plans...

Journalists Criticize AI Hype in Media

Summary Journalists are contributing to the hype and...