• Home
  • Mobiles
  • Mobiles News
  • aCropalypse Flaw Allows Recovery of Sensitive Data Removed From Pixel Screenshots, Researchers Say

aCropalypse Flaw Allows Recovery of Sensitive Data Removed From Pixel Screenshots, Researchers Say 6j1z60

Google has reportedly patched the aCropalypse flaw on Pixel 4a, Pixel 5a, Pixel 7, and Pixel 7 Pro smartphones. 2r4l45

aCropalypse Flaw Allows Recovery of Sensitive Data Removed From Pixel Screenshots, Researchers Say

Photo Credit: Google 4650x

The aCropalypse flaw has existed for the past five years, according to researchers

Highlights
  • The aCropalypse vulnerability affects the markup tool on Pixel phones
  • A tool to demonstrate aCropalypse allows s to recover removed details
  • Owners of select Pixel phone can install an update that blocks the flaw
ment

Pixel smartphones were previously affected by a security flaw that could allow any to restore sensitive details cropped or redacted from screenshots, according to data shared by security researchers. A security flaw in Google's markup tool for Pixel smartphones allowed edited┬аscreenshot images to retain some of the original information, letting s recover details that were previously obfuscated by the sender. The vulnerability, which┬аhas existed for several years, has now been patched by Google on currently ed Pixel handsets.

Security researchers┬аSimon Aarons and David Buchanan discovered a security flaw dubbed┬аaCropalypse,┬аthat affects the markup tool used to crop, edit, and highlight┬аscreenshots on Pixel handsets. According to Android 10 introduced some changes to the system that caused data that had been edited out from screenshot┬аto remain in the image. As a result, that data can be recovered by any who received the image, including strangers on the Internet.

In a thread on Twitter, Aarons explained how the aCropalypse┬аvulnerability works┬аusing an image he sent to┬аDiscord Retr0id using┬аthe popular communication app. An image of a credit card that has been cropped and redacted with the "black pen" tool is shown to be ed, then subjected to a recovery process that results in an uncropped image of a fake bank website with the same credit card, along with its number visible.

According to Aarons, if the edited screenshot in PNG format has a smaller file size, as is the case with many cropped images, then┬атАЬthe trailing portion of the original file is left behind, after the new file is supposed to have endedтАЭ. This trailing portion of the file can then be recovered, he adds. The researcher has also published a tool that demonstrates how the aCropalypse┬аvulnerability functions, allowing s to a screenshot to try and recover the original file.

Meanwhile, a┬а9to5Google report citing an early access version of an FAQ page┬аfor the vulnerability, states that not all images shared online are affected by the image. Some platforms, such as Twitter, process all ed images in such a way that it is not affected by the aCropalypse┬аsecurity flaw. However, on platforms like Discord that share images as-is, s who have shared screenshots using their Pixel smartphones since Android 10 could be affected by the vulnerability.

Owners of the┬аPixel 7 Pro, can update to the latest March security release to install a security fix for the flaw┬а(CVE-2023-21036) which has a "high"┬аseverity classification, as per the report. However, there's no word from Google┬аon when other ed Pixel phones will receive the fixes, or whether the company will update Pixel handsets that are no longer receiving software updates with a fix for the┬аflaw.┬а


After facing headwinds in India last year, Xiaomi is all set to take on the competition in 2023. What are the company's plans for its wide product portfolio and its Make in India commitment in the country? We discuss this and more on Orbital, the Gadgets 360 podcast. Orbital is available on Spotify, Gaana, JioSaavn, Google Podcasts, Apple Podcasts, Amazon Music and wherever you get your podcasts.
links may be automatically generated - see our ethics statement for details.

Google Pixel 4a 472m38

  • REVIEW
  • KEY SPECS
  • NEWS
  • Design
  • Display
  • Software
  • Performance
  • Battery Life
  • Camera
  • Value for Money
  • Good
  • Reliable camera performance
  • Lean software with guaranteed updates
  • Stereo speakers
  • Vivid OLED display
  • Light, built well
  • Bad
  • Relatively low battery capacity
  • No ultra-wide camera
Display 5.81-inch
Processor Qualcomm Snapdragon 730G
Front Camera 8-megapixel
Rear Camera 12.2-megapixel
RAM 6GB
Storage 128GB
Battery Capacity 3140mAh
OS Android 10
Resolution 1080x2340 pixels

Google Pixel 7 f2s71

  • REVIEW
  • KEY SPECS
  • NEWS
  • Design
  • Display
  • Software
  • Performance
  • Battery Life
  • Camera
  • Value for Money
  • Good
  • Sharp, 90Hz display
  • Good quality cameras
  • Good gaming performance
  • Bloatware-free software, timely updates
  • Good battery life
  • IP68 rating
  • Bad
  • Video recording could be better
  • Gets warm under load
  • No bundled charger
  • Relatively slow charging
Display 6.30-inch
Processor Google Tensor G2
Front Camera 10.8-megapixel
Rear Camera 50-megapixel + 12-megapixel
RAM 8GB
Storage 128GB
OS Android 13
Resolution 1080x2400 pixels

Google Pixel 7 Pro p2x5s

  • REVIEW
  • KEY SPECS
  • NEWS
  • Design
  • Display
  • Software
  • Performance
  • Battery Life
  • Camera
  • Value for Money
  • Good
  • Sharp, 120Hz display
  • Good quality cameras
  • Good gaming performance
  • Bloatware-free software, timely updates
  • design, IP68 rating
  • Bad
  • Gets warm under load
  • No bundled charger
  • Underwhelming battery life
  • Relatively slow charging
Display 6.70-inch
Processor Google Tensor G2
Front Camera 10.8-megapixel
Rear Camera 50-megapixel + 48-megapixel + 12-megapixel
RAM 12GB
Storage 128GB
OS Android 13
Resolution 1440x3120 pixels
Comments

For the latest reviews, follow Gadgets 360 on X, Facebook, WhatsApp, Threads and Google News. For the latest videos on gadgets and tech, subscribe to our YouTube channel. If you want to know everything about top influencers, follow our in-house Who'sThat360 on Instagram and YouTube.

Further reading: Vulnerabilities
David Delima
As a writer on technology with Gadgets 360, David Delima is interested in open-source technology, cybersecurity, consumer privacy, and loves to read and write about how the Internet works. David can be ed via email at [email protected],┬аon Twitter at @DxDavey, and Mastodon at mstdn.social/@delima. More
Infinix Hot 30i Key Specifications Leak Ahead of March 27 India Launch
Bitcoin at Over $27,000 Hits Peak Price So Far in 2023, Altcoins See Small Losses
Facebook Gadgets360 Twitter Share Tweet Snapchat LinkedIn Reddit Comment google-newsGoogle News

ment

Follow Us

ment

┬й Copyright Red Pixels Ventures Limited 2025. All rights reserved.
Trending Products┬а┬╗
Latest Tech News┬а┬╗