Get all your news in one place.
100’s of premium titles.
One app.
Start reading
TechRadar
TechRadar
Craig Hale

This Google Pixel flaw could let hackers undo all your photo cropping

Google Pixel 7

A vulnerability has been discovered affecting Google Pixel users with a vulnerability that could have exposed users’ most sensitive information and may continue to do so in certain cases.

Though Google issued a fix to CVE-2023-21036 in its March update, the high-risk vulnerability has been allowing hackers to undo many edits made to images on Pixel devices.

It specifically relates to the Markup feature, which allows users to edit photos such as to eliminate sensitive information from images like bank cards, either by cropping certain aspects or applying visual layers over elements.

Pixel Markup vulnerability

According to reverse engineers Simon Aarons and David Buchanan, who discovered the issue, with an edited - and seemingly secure - image, a malicious actor could in some cases reverse such edits to expose sensitive information in a vulnerability that’s being dubbed ‘acropalypse.’

While many of us prefer sharing images via channels that prefer some or all of their metadata, such as Discord, this has proven less secure, exposing the vulnerability. It’s worth mentioning that Discord fixed the issue in mid-January 2023. By contrast, platforms like Twitter process images in a different way in turn leaving edits un-reversible. 

The flaw stems from Android 9 Pie which coincides with the Pixel 3 family, meaning that 4, 5, 6, and latest 7 model families are also said to have been affected.

Given the age of some devices, only the Pixel 4a and newer currently receive security updates leaving some earlier models including the 4 and everything before it without official support, thus still vulnerable.

Furthermore, edited screenshots sent before updates were rolled out remain vulnerable and as such, should be removed where possible.

TechRadar Pro has asked Google to confirm whether there are still any devices that continue to expose the vulnerability, and if so, whether they will be patched.

Sign up to read this article
Read news from 100’s of titles, curated specifically for you.
Already a member? Sign in here
Related Stories
Top stories on inkl right now
One subscription that gives you access to news from hundreds of sites
Already a member? Sign in here
Our Picks
Fourteen days free
Download the app
One app. One membership.
100+ trusted global sources.