Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    Final Four-bound FAU’s AD, Brian White, is still speechless

    March 26, 2023

    DPartners Review – CPA Network

    March 26, 2023

    ChatGPT started a new kind of AI race — and made text boxes cool again

    March 26, 2023
    Facebook Twitter Instagram
    Facebook Twitter Instagram
    EasyDailyCrypto – Today Crypto | Bitcoin | Global World News
    Button
    • Home
    • Features
      • Contact
    • Crypto
    • Politics

      Trump Whacks Out In Waco Over Looming Indictment

      March 26, 2023

      Trump Rally Crowd Cheers Ted Nugent Calling Zelenskyy A Homosexual Weirdo

      March 26, 2023

      Jim Jordan’s Weaponization Of DOJ Report Blows Up In His Face

      March 26, 2023

      DC City Council Embarrassed After Push for Liberal Crime Bill Backfires

      March 25, 2023

      Leftist Groups Tapping $1 Billion to Vastly Expand the Private Financing of Public Elections

      March 25, 2023
    • Technology
      1. Crypto
      2. Politics
      3. Business
      4. Lifestyle
      5. View All

      EUL Jumps 35% as Euler Finance Hacker Returns Another $100M Worth of Ethereum

      March 26, 2023

      Ripple (XRP) Soars 21% Weekly, Bitcoin (BTC) Stalls Above $27K: Weekend Watch

      March 26, 2023

      Solanaland Set To Commence Pre-sale Of Utility Token

      March 26, 2023

      Animoca Brands Slashes Target of Metaverse Fund by 20%: Report

      March 26, 2023

      Trump Whacks Out In Waco Over Looming Indictment

      March 26, 2023

      Trump Rally Crowd Cheers Ted Nugent Calling Zelenskyy A Homosexual Weirdo

      March 26, 2023

      Jim Jordan’s Weaponization Of DOJ Report Blows Up In His Face

      March 26, 2023

      DC City Council Embarrassed After Push for Liberal Crime Bill Backfires

      March 25, 2023

      Poland’s prime minister confident US Republicans will not backtrack on Ukraine

      March 26, 2023

      The unstoppable rise of government rescues

      March 26, 2023

      European investors bet on defence as war creates opportunities for growth

      March 26, 2023

      Jay Powell and Janet Yellen struggle to calm nerves in banking crisis

      March 26, 2023

      Should Soy Sauce Be Refrigerated?

      March 25, 2023

      A 3-Step Guide to Making Paleo Salad Dressing from Scratch

      March 23, 2023

      Where to Stay, Eat, and Shop in Amsterdam Right Now

      March 23, 2023

      The 21-Day Gut-Feeling Plan

      March 21, 2023

      ChatGPT started a new kind of AI race — and made text boxes cool again

      March 26, 2023

      The layoffs will continue until (investor) morale improves

      March 26, 2023

      Threading the needle: Exploring 5 ideas with the founders of LGBT+ VC

      March 26, 2023

      Twitter Blue relaunched has made just $11M on mobile in its first 3 months

      March 26, 2023
    EasyDailyCrypto – Today Crypto | Bitcoin | Global World News
    Beranda » Google Pixel ‘aCropalypse’ exploit reverses edited parts of screenshots
    Technology

    Google Pixel ‘aCropalypse’ exploit reverses edited parts of screenshots

    EASYDAILYCRYPTO NEWSBy EASYDAILYCRYPTO NEWSMarch 20, 2023No Comments4 Mins Read
    Facebook Twitter Pinterest LinkedIn Tumblr Email
    Share
    Facebook Twitter LinkedIn Pinterest Email

    A security flaw affecting the Google Pixel’s default screenshot editing utility, Markup, allows images to become partially “unedited,” potentially revealing the personal information users chose to hide, as spotted earlier by 9to5Google and Android Police. The vulnerability, which was discovered by reverse engineers Simon Aaarons and David Buchanan, has since been patched by Google but still has widespread implications for the edited screenshots shared prior to the update.

    As detailed in a thread Aaarons posted on Twitter, the aptly-named “aCropalypse” flaw makes it possible for someone to partially recover PNG screenshots edited in Markup. That includes scenarios where someone may have used the tool to crop or scribble out their name, address, credit card number, or any other kind of personal information the screenshot may contain. A bad actor could exploit this vulnerability to reverse some of those changes and obtain information users thought they had been hiding.

    In a forthcoming FAQ page obtained early by 9to5Google, Aarons and Buchanan explain that this flaw exists because Markup saves the original screenshot in the same file location as the edited one, and never deletes the original version. If the edited version of the screenshot is smaller than the original, “the trailing portion of the original file is left behind, after the new file is supposed to have ended.”

    According to Buchanan, this bug first emerged about five years ago, around the same time Google introduced Markup with the Android 9 Pie update. That’s what makes this all the worse, as years-worth of older screenshots edited with Markup and shared on social media platforms could be vulnerable to the exploit.

    The FAQ page states that while certain sites, including Twitter, re-process the images posted on the platforms and strip them of the flaw, others, such as Discord, don’t. Discord only just patched the exploit in a recent January 17th update, which means edited images shared to the platform before that date may be at risk. It’s still not clear whether there are any other affected sites or apps and if so, which ones they are.

    The example posted by Aarons (embedded above) shows a cropped image of a credit card posted to Discord, which also has the card number blocked out using the Markup tool’s black pen. Once Aarons downloads the image and exploits the aCropalypse vulnerability, the top part of the image becomes corrupted, but he can still see the pieces that were edited out in Markup, including the credit card number. You can read more about the technical details of the flaw in Buchanan’s blog post.

    After Aarons and Buchanan reported the flaw (CVE-2023-21036) to Google in January, the company patched the issue in a March security update for the Pixel 4A, 5A, 7, and 7 Pro with its severity classified as “high.” It’s unclear when this update will arrive for the other devices affected by the vulnerability, and Google didn’t immediately respond to The Verge’s request for more information. If you want to see how the issue works for yourself, you can upload a screenshot edited with a non-updated version of the Markup tool to this demo page created by Aarons and Buchanan. Or, you can check out some of the scary examples posted on the web.

    This flaw came to light just days after Google’s security team found that the Samsung Exynos modems included in the Pixel 6, Pixel 7, and select Galaxy S22 and A53 models could allow hackers to “remotely compromise” devices using just a victim’s phone number. Google has since patched the issue in its March update, although this still isn’t available for the Pixel 6, 6 Pro, and 6A devices yet.

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    EASYDAILYCRYPTO NEWS
    • Website

    Daily update exclusive News about the latest Crypto, Bitcoin, Ethereum, Blockchain, NFTs, Altcoin, Trendings News with the latest Global World News today

    Related Posts

    ChatGPT started a new kind of AI race — and made text boxes cool again

    March 26, 2023

    The layoffs will continue until (investor) morale improves

    March 26, 2023

    Threading the needle: Exploring 5 ideas with the founders of LGBT+ VC

    March 26, 2023

    Leave A Reply Cancel Reply

    Advertisement
    Our Picks

    The Internet Archive has lost its first fight to scan and lend e-books like a library

    March 25, 2023

    TikTok ban: all the news on the US’s crackdown on the video platform

    March 22, 2023

    Mozilla launches a new startup focused on ‘trustworthy’ AI

    March 22, 2023

    3 tips for crypto startups preparing for continued compliance

    March 22, 2023
    • Facebook
    • Twitter
    • Pinterest
    • Instagram
    • YouTube
    • Vimeo
    Don't Miss
    Sports

    Final Four-bound FAU’s AD, Brian White, is still speechless

    By EASYDAILYCRYPTO NEWSMarch 26, 202300 Views

    From the eighth-floor lobby of Manhattan’s New York Marriott Marquis hotel, Florida Atlantic athletic director…

    DPartners Review – CPA Network

    March 26, 2023

    ChatGPT started a new kind of AI race — and made text boxes cool again

    March 26, 2023

    Poland’s prime minister confident US Republicans will not backtrack on Ukraine

    March 26, 2023

    Subscribe to Updates

    Get the latest creative news from SmartMag about art & design.

    About Us
    About Us

    Update Breaking Crypto News about the latest Crypto daily, Ethereum, Blockchain, NFTs, Altcoin, Trends and Happenings including the latest World News. Exclusive crypto coin news in Easy Daily Crypto.

    Email Us: [email protected]
    Contact: +62-822-7359-8787

    Our Picks

    Final Four-bound FAU’s AD, Brian White, is still speechless

    March 26, 2023

    DPartners Review – CPA Network

    March 26, 2023

    ChatGPT started a new kind of AI race — and made text boxes cool again

    March 26, 2023
    Crypto

    EUL Jumps 35% as Euler Finance Hacker Returns Another $100M Worth of Ethereum

    March 26, 2023

    Ripple (XRP) Soars 21% Weekly, Bitcoin (BTC) Stalls Above $27K: Weekend Watch

    March 26, 2023

    Solanaland Set To Commence Pre-sale Of Utility Token

    March 26, 2023
    Facebook Twitter Instagram Pinterest
    • Politics
    • Business
    • Crypto
    • Technology
    © 2023 All Right Reserved. Designed by EasyDailyCrypto.com.

    Type above and press Enter to search. Press Esc to cancel.