/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

Researchers detail “Pixnapping”, a new covert attack to steal 2FA codes and other private data on Android; Google's September patch only partially mitigates it

Android devices are vulnerable to a new attack that can covertly steal 2FA codes, location timelines, and other private data in less than 30 seconds.

Ars Technica Dan Goodin

Context & Ripple Effects

Pixnapping extends a recurring Android security problem: prior research showed that apps could obtain Google Authenticator codes through screenshots of one-time codes, while Cerberus demonstrated malware targeting authenticator-generated passwords.

The notable change is that Google has issued a mitigation but acknowledges it is incomplete. That makes the issue less a one-off disclosure than a test of how quickly Android’s defenses can close residual attack paths.

First-order effects

  • Android users remain exposed to theft of authentication codes, location history, and other on-screen private data through vectors not covered by Google’s September mitigation.
  • Google must address the remaining exploitable paths; until then, a partial patch does not fully restore the protection users expect from 2FA codes on their devices.

Second-order effects

  • Organizations relying on app-based one-time codes may reassess how much account protection they can attribute to a code once it is displayed on a compromised device, especially given earlier Android malware aimed at authenticator passwords.
  • The disclosure raises pressure on Android security teams and app developers to reduce sensitive-data exposure through screen-level interfaces and to speed remediation beyond an initial partial fix.

Third-order effects

  • If recurring code-theft techniques continue to bypass device-level safeguards, mobile authentication will increasingly need layered defenses rather than treating an on-device one-time code as a sufficient trust boundary.
  • The pattern favors security architectures that minimize the value of captured display data, while making patch completeness and device update delivery more consequential competitive factors.

The trend: Pixnapping is another data point in the shift from attacking credentials directly to extracting the sensitive information users view inside mobile apps.

Discussion

  • @tyleraking.com Tyler King on bluesky
    Researchers have devised a hack that uses a malicious Android app to read data from any other app installed on the phone.  Google released a patch but the researchers say their methods still work.
  • @urd00m @urd00m on bluesky
    Notably, our end-to-end attack against Google Authenticator can leak a 2FA code in under 30 seconds - all while showing the user a normal looking app.
  • @urd00m @urd00m on bluesky
    We have demonstrated Pixnapping attacks on Google and Samsung phones and end-to-end recovery of sensitive data from websites including Gmail and Google Accounts and apps including Signal and Google Authenticator.
  • @urd00m @urd00m on bluesky
    Pixnapping exploits Android APIs and a hardware side channel to render, compute on, and leak (one by one) any pixels that can be displayed by a target app on the screen.  Pixnapping requires no permissions.
  • @urd00m @urd00m on bluesky
    We found a way for any Android app to stealthily leak information displayed by other apps or arbitrary websites (e.g., emails, 2FA codes, and private messages).  How is that possible?  With #pixnapping!  —  www.pixnapping.com
  • @urd00m @urd00m on bluesky
    For the academic paper, a demo video, and an FAQ, check out our website (pixnapping.com).  —  And if you are at ACM CCS 2025 this week, come see my talk at 9 AM on October 16th!
  • @campuscodi@mastodon.social Catalin Cimpanu on mastodon
    “Pixnapping is a new class of attacks that allows a malicious Android app to stealthily leak information displayed by other Android apps or arbitrary websites.”  —  Tested to steal data from Gmail, Google Accounts, Signal, Google Authenticator, Venmo, and Google Maps  —  https://…
  • r/cybersecurity r on reddit
    Hackers can steal 2FA codes and private messages from Android phones |  Malicious app required to make “Pixnapping” attack work requires no permissions.
  • r/technology r on reddit
    Hackers can steal 2FA codes and private messages from Android phones |  Malicious app required to make “Pixnapping” attack work requires no permissions
  • r/technews r on reddit
    Hackers can steal 2FA codes and private messages from Android phones |  Malicious app required to make “Pixnapping” attack work requires no permissions.
  • r/Android r on reddit
    Hackers can steal 2FA codes and private messages from Android phones |  Malicious app required to make “Pixnapping” attack work requires no permissions.