Researchers detail a recently fixed aCropalypse vulnerability in Google Pixel's Markup tool that lets some screenshots be retroactively unredacted or uncropped
Besides the Samsung Exynos modem issue, Android 13 QPR2 with the March 2023 security update fixes a vulnerability with the Pixel's Markup screenshot tool.
Context & Ripple Effects
This report documents a privacy failure in a built-in Pixel editing workflow and its inclusion in Google’s March 2023 update. A subsequent researcher write-up on the March fix reinforced that the issue concerned information users believed they had removed from screenshots.
The risk was not confined to one device brand’s user expectations: a similar apparent flaw in Windows 11’s Snipping Tool suggested that image-editing pipelines can preserve data beyond the visible crop or redaction.
First-order effects
- Pixel users who install Android 13 QPR2 with the March 2023 security update receive a fix for Markup’s vulnerable handling of edited screenshots.
- People who shared affected screenshots before updating may need to treat their apparent crops or redactions as unreliable and replace sensitive copies where practical.
Second-order effects
- The Windows parallel puts pressure on screenshot-tool makers to test whether save and export operations actually discard removed image data, rather than merely hiding it.
- Organizations that use screenshots for support, incident reports, or document review may tighten guidance on redacting sensitive material and favor tools that verify the final exported file.
Third-order effects
- If comparable bugs continue to surface, privacy claims around capture and annotation tools will increasingly depend on provenance and deletion guarantees at export time, not on what the on-screen preview shows.
- Security patching for consumer devices may be judged more by whether it protects data already created and shared than by whether it only prevents future exposure; this case does not establish how broadly that standard will be adopted.
The trend: aCropalypse is part of a broader shift toward treating image capture, editing, and export pipelines as privacy-critical trust boundaries.