Researchers detail “Pixnapping”, a new covert attack to steal 2FA codes and other private data on Android; Google's September patch only partially mitigates it
Android devices are vulnerable to a new attack that can covertly steal 2FA codes, location timelines, and other private data in less than 30 seconds.
Ars TechnicaDan Goodin
Context & Ripple Effects
Pixnapping extends a recurring Android security problem: prior research showed that apps could obtain Google Authenticator codes through screenshots of one-time codes, while Cerberus demonstrated malware targeting authenticator-generated passwords.
The notable change is that Google has issued a mitigation but acknowledges it is incomplete. That makes the issue less a one-off disclosure than a test of how quickly Android’s defenses can close residual attack paths.
First-order effects
Android users remain exposed to theft of authentication codes, location history, and other on-screen private data through vectors not covered by Google’s September mitigation.
Google must address the remaining exploitable paths; until then, a partial patch does not fully restore the protection users expect from 2FA codes on their devices.
Second-order effects
Organizations relying on app-based one-time codes may reassess how much account protection they can attribute to a code once it is displayed on a compromised device, especially given earlier Android malware aimed at authenticator passwords.
The disclosure raises pressure on Android security teams and app developers to reduce sensitive-data exposure through screen-level interfaces and to speed remediation beyond an initial partial fix.
Third-order effects
If recurring code-theft techniques continue to bypass device-level safeguards, mobile authentication will increasingly need layered defenses rather than treating an on-device one-time code as a sufficient trust boundary.
The pattern favors security architectures that minimize the value of captured display data, while making patch completeness and device update delivery more consequential competitive factors.
The trend: Pixnapping is another data point in the shift from attacking credentials directly to extracting the sensitive information users view inside mobile apps.
Researchers have devised a hack that uses a malicious Android app to read data from any other app installed on the phone. Google released a patch but the researchers say their methods still work.
We have demonstrated Pixnapping attacks on Google and Samsung phones and end-to-end recovery of sensitive data from websites including Gmail and Google Accounts and apps including Signal and Google Authenticator.
Pixnapping exploits Android APIs and a hardware side channel to render, compute on, and leak (one by one) any pixels that can be displayed by a target app on the screen. Pixnapping requires no permissions.
We found a way for any Android app to stealthily leak information displayed by other apps or arbitrary websites (e.g., emails, 2FA codes, and private messages). How is that possible? With #pixnapping! — www.pixnapping.com
For the academic paper, a demo video, and an FAQ, check out our website (pixnapping.com). — And if you are at ACM CCS 2025 this week, come see my talk at 9 AM on October 16th!
“Pixnapping is a new class of attacks that allows a malicious Android app to stealthily leak information displayed by other Android apps or arbitrary websites.” — Tested to steal data from Gmail, Google Accounts, Signal, Google Authenticator, Venmo, and Google Maps — https://…
Hackers can steal 2FA codes and private messages from Android phones | Malicious app required to make “Pixnapping” attack work requires no permissions.
Hackers can steal 2FA codes and private messages from Android phones | Malicious app required to make “Pixnapping” attack work requires no permissions.
Hackers can steal 2FA codes and private messages from Android phones | Malicious app required to make “Pixnapping” attack work requires no permissions.