FacebookInstagramTwitterContact

 

Seven Teens With Alleged 'Extremist Ideology' Arrested In Sydney Raids           >>           Seven Teens With Alleged 'Extremist Ideology' Arrested In Sydney Raids           >>           Launching of A.I. Diabetic Retinopathy Screening Services           >>           Honey: An Amazing Superfood With Many Health Benefits           >>           Exploring The Benefits Of FASTING For Treating COVID-19 And Vaccine Injuries           >>           Milan Wants To Ban Gelato, Pizza And Other Italian Favourites (Sort Of)           >>           Skai Jackson Reveals Where She Stands With Her Jessie Costars Today           >>           Billie Eilish Details When She Realized She Wanted Her “Face In A Vagina”           >>           Messages of Condolences           >>           Japan's SLIM Moon Lander Defies Death To Survive 3rd Frigid Lunar Night (Image)           >>          

 

SHARE THIS ARTICLE




REACH US


GENERAL INQUIRY

[email protected]

 

ADVERTISING

[email protected]

 

PRESS RELEASE

[email protected]

 

HOTLINE

+673 222-0178 [Office Hour]

+673 223-6740 [Fax]

 



Upcoming Events





Prayer Times


The prayer times for Brunei-Muara and Temburong districts. For Tutong add 1 minute and for Belait add 3 minutes.


Imsak

: 05:01 AM

Subuh

: 05:11 AM

Syuruk

: 06:29 AM

Doha

: 06:51 AM

Zohor

: 12:32 PM

Asar

: 03:44 PM

Maghrib

: 06:32 PM

Isyak

: 07:42 PM

 



The Business Directory


 

 



Security & Privacy


  Home > Security & Privacy


Google Pixel Vulnerability Allows Bad Actors To Undo Markup Screenshot Edits And Redactions


Sam Rutherford/Engadget

 


 March 21st, 2023  |  10:13 AM  |   415 views

CALIFORNIA, UNITED STATES

 

Google has addressed the exploit, but years of images could still be at risk.

 

When Google began rolling out Android’s March security patch earlier this week, the company addressed a “High” severity vulnerability involving the Pixel’s Markup screenshot tool. Over the weekend, Simon Aarons and David Buchanan, the reverse engineers who discovered CVE-2023-21036, shared more information about the security flaw, revealing Pixel users are still at risk of their older images being compromised due to the nature of Google’s oversight.

 

In short, the “aCropalypse” flaw allowed someone to take a PNG screenshot cropped in Markup and undo at least some of the edits in the image. It’s easy to imagine scenarios where a bad actor could abuse that capability. For instance, if a Pixel owner used Markup to redact an image that included sensitive information about themselves, someone could exploit the flaw to reveal that information. You can find the technical details on Buchanan’s blog.

 

According to Buchanan, the flaw has existed for about five years, coinciding with the release of Markup alongside Android 9 Pie in 2018. And therein lies the problem. While March’s security patch will prevent Markup from compromising future images, some screenshots Pixel users may have shared in the past are still at risk.

 

It’s hard to say how concerned Pixel users should be about the flaw. According to a forthcoming FAQ page Aarons and Buchanan shared with 9to5Google and The Verge, some websites, including Twitter, process images in such a way that someone could not exploit the vulnerability to reverse edit a screenshot or image. Users on other platforms aren’t so lucky. Aarons and Buchanan specifically identify Discord, noting the chat app did not patch out the exploit until its recent January 17th update. At the moment, it’s unclear if images shared on other social media and chat apps were left similarly vulnerable.

 

Google did not immediately respond to Engadget’s request for comment and more information. The March security update is currently available on the Pixel 4a, 5a, 7 and 7 Pro, meaning Markup can still produce vulnerable images on some Pixel devices. It’s unclear when Google will push the patch to other Pixel devices. If you own a Pixel phone without the patch, avoid using Markup to share sensitive images.

 


 

Source:
courtesy of ENGADGET

by Igor Bonifacic

 

If you have any stories or news that you would like to share with the global online community, please feel free to share it with us by contacting us directly at [email protected]

 

Related News


Lahad Datu Murder: Remand Of 13 Students Extende

 2024-03-30 07:57:54

Seven Teens With Alleged 'Extremist Ideology' Arrested In Sydney Raids

 2024-04-25 10:57:21

Boycotts Aren't The Only Way To Hold Companies Accountable

 2024-04-25 01:24:19