Tech Wavo
  • Home
  • Technology
  • Computers
  • Gadgets
  • Mobile
  • Apps
  • News
  • Financial
  • Stock
Tech Wavo
No Result
View All Result

A New Attack Lets Hackers Steal 2-Factor Authentication Codes From Android Phones

Tech Wavo by Tech Wavo
October 14, 2025
in Computers
0


Android devices are vulnerable to a new attack that can covertly steal two-factor authentication codes, location timelines, and other private data in less than 30 seconds.

The new attack, named Pixnapping by the team of academic researchers who devised it, requires a victim to first install a malicious app on an Android phone or tablet. The app, which requires no system permissions, can then effectively read data that any other installed app displays on the screen. Pixnapping has been demonstrated on Google Pixel phones and the Samsung Galaxy S25 phone and likely could be modified to work on other models with additional work. Google released mitigations last month, but the researchers said a modified version of the attack works even when the update is installed.

Like Taking a Screenshot

Pixnapping attacks begin with the malicious app invoking Android programming interfaces that cause the authenticator or other targeted apps to send sensitive information to the device screen. The malicious app then runs graphical operations on individual pixels of interest to the attacker. Pixnapping then exploits a side channel that allows the malicious app to map the pixels at those coordinates to letters, numbers, or shapes.

“Anything that is visible when the target app is opened can be stolen by the malicious app using Pixnapping,” the researchers wrote on an informational website. “Chat messages, 2FA codes, email messages, etc. are all vulnerable since they are visible. If an app has secret information that is not visible (e.g., it has a secret key that is stored but never shown on the screen), that information cannot be stolen by Pixnapping.”

The new attack class is reminiscent of GPU.zip, a 2023 attack that allowed malicious websites to read the usernames, passwords, and other sensitive visual data displayed by other websites. It worked by exploiting side channels found in GPUs from all major suppliers. The vulnerabilities that GPU.zip exploited have never been fixed. Instead, the attack was blocked in browsers by limiting their ability to open iframes, an HTML element that allows one website (in the case of GPU.zip, a malicious one) to embed the contents of a site from a different domain.

Pixnapping targets the same side channel as GPU.zip, specifically the precise amount of time it takes for a given frame to be rendered on the screen.

Previous Post

OpenAI’s Sam Altman says kids born in 2025 won’t be smarter than artificial intelligence

Next Post

Andrej Karpathy Releases ‘nanochat’: A Minimal, End-to-End ChatGPT-Style Pipeline You Can Train in ~4 Hours for ~$100

Next Post
Andrej Karpathy Releases ‘nanochat’: A Minimal, End-to-End ChatGPT-Style Pipeline You Can Train in ~4 Hours for ~$100

Andrej Karpathy Releases 'nanochat': A Minimal, End-to-End ChatGPT-Style Pipeline You Can Train in ~4 Hours for ~$100

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

The latest Roku update adds AI-powered voice control and better search

by Tech Wavo
October 15, 2025
0
The latest Roku update adds AI-powered voice control and better search
Computers

Roku just announced a robust software update coming to many of its devices. These are free upgrades, with search getting...

Read more

Oracle has just unveiled the “largest AI supercomputer in the world” – and it really is huge

by Tech Wavo
October 15, 2025
0
Oracle has just unveiled the “largest AI supercomputer in the world” – and it really is huge
Computers

As the AI boom continues and around one month after Microsoft revealed the “world’s most powerful data center,” Oracle has...

Read more

Where to buy Nintendo Switch 2 Pokémon Legends Z-A bundles – stock checks and updates on the next big Switch 2 bundle

by Tech Wavo
October 15, 2025
0
Where to buy Nintendo Switch 2 Pokémon Legends Z-A bundles – stock checks and updates on the next big Switch 2 bundle
Computers

The hugely anticipated new Pokémon game is out this week, and many of you fine folk may be wondering where...

Read more

Threads is getting group chats as messaging rolls out to the EU

by Tech Wavo
October 15, 2025
0
Threads now has more than 400 million monthly active users
Computers

Shortly after its addition of direct messages this summer, Instagram Threads is adding support for group messaging with up to...

Read more

Site links

  • Home
  • About Us
  • Contact Us
  • Privacy Policy
  • Terms of use
  • Home
  • About Us
  • Contact Us
  • Privacy Policy
  • Terms of use

No Result
View All Result
  • Home
  • Technology
  • Computers
  • Gadgets
  • Mobile
  • Apps
  • News
  • Financial
  • Stock