This Google Pixel flaw could let hackers undo all your photo cropping


A vulnerability has been discovered affecting Google Pixel users with a vulnerability that could have exposed users’ most sensitive information and may continue to do so in certain cases.
Though Google issued a fix to CVE-2023-21036 in its March update (opens in new tab), the high-risk vulnerability has been allowing hackers to undo many edits made to images on Pixel devices.
It specifically relates to the Markup feature, which allows users to edit photos such as to eliminate sensitive information from images like bank cards, either by cropping certain aspects or applying visual layers over elements.
Pixel Markup vulnerability
According to reverse engineers Simon Aarons (opens in new tab) and David Buchanan (opens in new tab), who discovered the issue, with an edited – and seemingly secure – image, a malicious actor could in some cases reverse such edits to expose sensitive information in a vulnerability that’s being dubbed ‘acropalypse.’
While many of us prefer sharing images via channels that prefer some or all of their metadata, such as Discord, this has proven less secure, exposing the vulnerability. It’s worth mentioning that Discord fixed the issue in mid-January 2023. By contrast, platforms like Twitter process images in a different way in turn leaving edits un-reversible.
The flaw stems from Android 9 Pie which coincides with the Pixel 3 family, meaning that 4, 5, 6, and latest 7 model families are also said to have been affected.
Given the age of some devices, only the Pixel 4a and newer currently receive security updates (opens in new tab) leaving some earlier models including the 4 and everything before it without official support, thus still vulnerable.
Furthermore, edited screenshots sent before updates were rolled out remain vulnerable and as such, should be removed where possible.
TechRadar Pro has asked Google to confirm whether there are still any devices that continue to expose the vulnerability, and if so, whether they will be patched.
A vulnerability has been discovered affecting Google Pixel users with a vulnerability that could have exposed users’ most sensitive information and may continue to do so in certain cases. Though Google issued a fix to CVE-2023-21036 in its March update (opens in new tab), the high-risk vulnerability has been allowing…
Recent Posts
- With the Humane AI Pin now dead, what does the Rabbit R1 need to do to survive?
- One of the best AI video generators is now on the iPhone – here’s what you need to know about Pika’s new app
- Apple’s C1 chip could be a big deal for iPhones – here’s why
- Rabbit shows off the AI agent it should have launched with
- Instagram wants you to do more with DMs than just slide into someone else’s
Archives
- February 2025
- January 2025
- December 2024
- November 2024
- October 2024
- September 2024
- August 2024
- July 2024
- June 2024
- May 2024
- April 2024
- March 2024
- February 2024
- January 2024
- December 2023
- November 2023
- October 2023
- September 2023
- August 2023
- July 2023
- June 2023
- May 2023
- April 2023
- March 2023
- February 2023
- January 2023
- December 2022
- November 2022
- October 2022
- September 2022
- August 2022
- July 2022
- June 2022
- May 2022
- April 2022
- March 2022
- February 2022
- January 2022
- December 2021
- November 2021
- October 2021
- September 2021
- August 2021
- July 2021
- June 2021
- May 2021
- April 2021
- March 2021
- February 2021
- January 2021
- December 2020
- November 2020
- October 2020
- September 2020
- August 2020
- July 2020
- June 2020
- May 2020
- April 2020
- March 2020
- February 2020
- January 2020
- December 2019
- November 2019
- September 2018
- October 2017
- December 2011
- August 2010