#Pixnapping
The malicious app required to make a “Pixnapping” attack work requires no permissions. www.wired.com/story/a-new-...
A New Attack Lets Hackers Steal 2-Factor Authentication Codes From Android Phones
The malicious app required to make a “Pixnapping” attack work requires no permissions.
www.wired.com
October 14, 2025 at 9:42 PM
Gotta love vulnerability branding

I is in your android pixnapping your TOTP codes
Pixnapping Attack
www.pixnapping.com
October 14, 2025 at 8:41 PM
Two great bits of academic attack work this week. The new one allows Android apps to see data displayed on the screen by other apps, including Google Authenticator codes. www.pixnapping.com
Pixnapping Attack
www.pixnapping.com
October 15, 2025 at 10:44 AM
The attack can covertly steal two-factor authentication codes, location timelines, and other sensitive data in under 30 seconds.
Hackers can steal 2FA codes and private messages from Android phones
Malicious app required to make “Pixnapping” attack work requires no permissions.
arstechnica.com
October 14, 2025 at 3:33 PM
"Pixnapping is a new class of attacks that allows a malicious Android app to stealthily leak information displayed by other Android apps or arbitrary websites."

Tested to steal data from Gmail, Google Accounts, Signal, Google Authenticator, Venmo, and Google Maps

www.pixnapping.com
October 14, 2025 at 12:29 PM
A new side-channel attack called Pixnapping enables a malicious Android app with no permissions to extract sensitive data by stealing pixels displayed by applications or websites, and reconstructing them to derive the content.
New Android Pixnapping attack steals MFA codes pixel-by-pixel
A new side-channel attack called Pixnapping enables a malicious Android app with no permissions to extract sensitive data by stealing pixels displayed by applications or websites, and reconstructing them to derive the content.
www.bleepingcomputer.com
October 14, 2025 at 6:47 PM
New Pixnapping Attack Steals 2FA Codes From Google Authenticator Within 30 Seconds
New Pixnapping Attack Steals 2FA Codes From Google Authenticator Within 30 Seconds
cybersecuritynews.com
October 14, 2025 at 2:48 PM
Researchers detail "Pixnapping", a new covert attack to steal 2FA codes and other private data on Android; Google's September patch only partially mitigates it (Dan Goodin/Ars Technica)

Main Link | Techmeme Permalink
October 14, 2025 at 1:15 AM
Pretty sure app is not going to say it’s a pixnapping app…
October 14, 2025 at 10:15 PM
Android 'Pixnapping' attack can capture app data like 2FA codes
Android 'Pixnapping' attack can capture app data like 2FA codes
GPU-based timing attack inspired by decade-old iframe technique Security researchers have resurrected a 12-year-old data-stealing attack on web browsers to pilfer sensitive info from Android devices.…
dlvr.it
October 13, 2025 at 2:07 PM
October 15, 2025 at 11:55 AM
Pixel-stealing “Pixnapping” attack targets Android devices #cybersecurity #hacking #news #infosec #security #technology #privacy
Pixel-stealing “Pixnapping” attack targets Android devices
Imagine if a rogue app could glimpse tiny bits of your screen—even the parts you thought were secure, like your 2FA codes.
www.malwarebytes.com
October 14, 2025 at 12:41 PM
Google has patched ‘Pixnapping’ attack in Android, further fix with December security update
Google has patched ‘Pixnapping’ attack in Android, further fix with December security update
Google is aware of a vulnerability that’s able to steal data from apps that are generally considered secure like Authenticator or Signal, using a new technique called “Pixnapping.” The vulnerability has been effective on several Google Pixel device models, as well as Samsung Galaxy devices. more…
9to5google.com
October 14, 2025 at 5:44 PM
Oh la belle vacherie.
Tout ce qui concerne l'affichage est super tricky à sécuriser complètement. Mais la règle d'or reste : "N'installez que le minimum d'applis."

arstechnica.com/security/202...
Hackers can steal 2FA codes and private messages from Android phones
Malicious app required to make “Pixnapping” attack work requires no permissions.
arstechnica.com
October 14, 2025 at 6:55 AM
Pixnapping Attack Lets Attackers Steal 2FA on Android
Pixnapping Attack Lets Attackers Steal 2FA on Android
The proof-of-concept exploit allows an attacker to steal sensitive data from Gmail, Google Accounts, Google Authenticator, Google Maps, Signal, and Venmo.
www.darkreading.com
October 14, 2025 at 10:27 PM
Android devices are vulnerable to a new attack that can covertly steal two-factor authentication codes, location timelines, and other private data in less than 30 seconds.
Hackers can steal 2FA codes and private messages from Android phones
Malicious app required to make “Pixnapping” attack work requires no permissions.
arstechnica.com
October 15, 2025 at 11:48 AM
Anything any #Android app can display is vulnerable to #Pixnapping attack—including #2FA codes. “It’s like Rowhammer, but for the screen,” quips one wag.

Google thought it had already fixed the previously undisclosed flaw. But the group’s demo says not. In #SBBlogwatch, we blur the pels:
#Pixnapping: Android Timing Attack Sends Google Back to the Drawing Board
If at first you don’t succeed: Researchers discover a new way to steal secrets from Android apps.
securityboulevard.com
October 14, 2025 at 3:21 PM
i said this a while back no one listened
arstechnica.com/security/202...
Hackers can steal 2FA codes and private messages from Android phones
Malicious app required to make “Pixnapping” attack work requires no permissions.
arstechnica.com
October 13, 2025 at 9:52 PM
October 14, 2025 at 5:18 PM