/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

Researchers detail a recently fixed aCropalypse vulnerability in Google Pixel's Markup tool that lets some screenshots be retroactively unredacted or uncropped

Besides the Samsung Exynos modem issue, Android 13 QPR2 with the March 2023 security update fixes a vulnerability with the Pixel's Markup screenshot tool.

9to5Google Abner Li

Context & Ripple Effects

This report documents a privacy failure in a built-in Pixel editing workflow and its inclusion in Google’s March 2023 update. A subsequent researcher write-up on the March fix reinforced that the issue concerned information users believed they had removed from screenshots.

The risk was not confined to one device brand’s user expectations: a similar apparent flaw in Windows 11’s Snipping Tool suggested that image-editing pipelines can preserve data beyond the visible crop or redaction.

First-order effects

  • Pixel users who install Android 13 QPR2 with the March 2023 security update receive a fix for Markup’s vulnerable handling of edited screenshots.
  • People who shared affected screenshots before updating may need to treat their apparent crops or redactions as unreliable and replace sensitive copies where practical.

Second-order effects

  • The Windows parallel puts pressure on screenshot-tool makers to test whether save and export operations actually discard removed image data, rather than merely hiding it.
  • Organizations that use screenshots for support, incident reports, or document review may tighten guidance on redacting sensitive material and favor tools that verify the final exported file.

Third-order effects

  • If comparable bugs continue to surface, privacy claims around capture and annotation tools will increasingly depend on provenance and deletion guarantees at export time, not on what the on-screen preview shows.
  • Security patching for consumer devices may be judged more by whether it protects data already created and shared than by whether it only prevents future exposure; this case does not establish how broadly that standard will be adopted.

The trend: aCropalypse is part of a broader shift toward treating image capture, editing, and export pipelines as privacy-critical trust boundaries.

Discussion

  • @delroth@mastodon.delroth.net Pierre Bourdon on mastodon
    CVE-2023-21036 / acropalypse is absolutely bonkers.  —  Apparently for 5+ years the cropping / editing tools for screenshots on Google Pixel phones was only overwriting the start of the screenshot PNG file, but not truncating. …
  • @itssimontime Simon Aarons on x
    Introducing acropalypse: a serious privacy vulnerability in the Google Pixel's inbuilt screenshot editing tool, Markup, enabling partial recovery of the original, unedited image data of a cropped and/or redacted screenshot. Huge thanks to @David3141593 for his help throughout! ht…