By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
MadisonyMadisony
Notification Show More
Font ResizerAa
  • Home
  • National & World
  • Politics
  • Investigative Reports
  • Education
  • Health
  • Entertainment
  • Technology
  • Sports
  • Money
  • Pets & Animals
Reading: A New Assault Lets Hackers Steal 2-Issue Authentication Codes From Android Telephones
Share
Font ResizerAa
MadisonyMadisony
Search
  • Home
  • National & World
  • Politics
  • Investigative Reports
  • Education
  • Health
  • Entertainment
  • Technology
  • Sports
  • Money
  • Pets & Animals
Have an existing account? Sign In
Follow US
2025 © Madisony.com. All Rights Reserved.
Technology

A New Assault Lets Hackers Steal 2-Issue Authentication Codes From Android Telephones

Madisony
Last updated: October 15, 2025 1:16 am
Madisony
Share
A New Assault Lets Hackers Steal 2-Issue Authentication Codes From Android Telephones
SHARE


Android units are susceptible to a brand new assault that may covertly steal two-factor authentication codes, location timelines, and different non-public information in lower than 30 seconds.

The brand new assault, named Pixnapping by the group of educational researchers who devised it, requires a sufferer to first set up a malicious app on an Android telephone or pill. The app, which requires no system permissions, can then successfully learn information that another put in app shows on the display screen. Pixnapping has been demonstrated on Google Pixel telephones and the Samsung Galaxy S25 telephone and sure might be modified to work on different fashions with extra work. Google launched mitigations final month, however the researchers mentioned a modified model of the assault works even when the replace is put in.

Like Taking a Screenshot

Pixnapping assaults start with the malicious app invoking Android programming interfaces that trigger the authenticator or different focused apps to ship delicate info to the system display screen. The malicious app then runs graphical operations on particular person pixels of curiosity to the attacker. Pixnapping then exploits a facet channel that permits the malicious app to map the pixels at these coordinates to letters, numbers, or shapes.

“Something that’s seen when the goal app is opened could be stolen by the malicious app utilizing Pixnapping,” the researchers wrote on an informational web site. “Chat messages, 2FA codes, e mail messages, and many others. are all susceptible since they’re seen. If an app has secret info that’s not seen (e.g., it has a secret key that’s saved however by no means proven on the display screen), that info can’t be stolen by Pixnapping.”

The brand new assault class is harking back to GPU.zip, a 2023 assault that allowed malicious web sites to learn the usernames, passwords, and different delicate visible information displayed by different web sites. It labored by exploiting facet channels present in GPUs from all main suppliers. The vulnerabilities that GPU.zip exploited have by no means been fastened. As an alternative, the assault was blocked in browsers by limiting their capacity to open iframes, an HTML aspect that permits one web site (within the case of GPU.zip, a malicious one) to embed the contents of a web site from a special area.

Pixnapping targets the identical facet channel as GPU.zip, particularly the exact period of time it takes for a given body to be rendered on the display screen.

Subscribe to Our Newsletter
Subscribe to our newsletter to get our newest articles instantly!
[mc4wp_form]
Share This Article
Email Copy Link Print
Previous Article Discover out who received ‘America’s Prime Younger Scientist’ for 2025 Discover out who received ‘America’s Prime Younger Scientist’ for 2025
Next Article A number of airports refuse to play DHS video blaming Democrats for presidency shutdown A number of airports refuse to play DHS video blaming Democrats for presidency shutdown

POPULAR

The Finest Amazon System and Kindle Black Friday Offers (2025): Paperwhite, Scribe, Echo Dot Max
Technology

The Finest Amazon System and Kindle Black Friday Offers (2025): Paperwhite, Scribe, Echo Dot Max

MTRCB bans biblical horror ‘The Carpenter’s Son’ from public screening
Investigative Reports

MTRCB bans biblical horror ‘The Carpenter’s Son’ from public screening

GOOG Inventory Soars To All Time Highs on NVDA Chip Comparision
Money

GOOG Inventory Soars To All Time Highs on NVDA Chip Comparision

Ohio State vs. Michigan prediction, odds: “The Recreation” 2025 picks from confirmed mannequin
Sports

Ohio State vs. Michigan prediction, odds: “The Recreation” 2025 picks from confirmed mannequin

Southern Lebanon villages missed by Pope’s go to : NPR
National & World

Southern Lebanon villages missed by Pope’s go to : NPR

If You Solely Educate College students One Factor About Writing
Education

If You Solely Educate College students One Factor About Writing

3 Shares I believe Ought to Be Included In Each Million Greenback Portfolio
Money

3 Shares I believe Ought to Be Included In Each Million Greenback Portfolio

You Might Also Like

The Finest Ventless Fireplaces for Cozy Vibes (2025)
Technology

The Finest Ventless Fireplaces for Cozy Vibes (2025)

The Lloyd from Solo Range pays critical homage to the freestanding mid-century enameled MCM Preway fireplaces that fetch 1000's on…

6 Min Read
Black Hat 2025: ChatGPT, Copilot, DeepSeek now create malware
Technology

Black Hat 2025: ChatGPT, Copilot, DeepSeek now create malware

Need smarter insights in your inbox? Join our weekly newsletters to get solely what issues to enterprise AI, knowledge, and…

12 Min Read
ChatGPT’s replace brings us one step nearer to residing within the film Her
Technology

ChatGPT’s replace brings us one step nearer to residing within the film Her

That “slight future” is, astonishingly, right here. In spite of everything, AI-powered chatbots truly are an actual factor now, and…

3 Min Read
Why Nicholas Thompson Made a Customized GPT to Run Quicker
Technology

Why Nicholas Thompson Made a Customized GPT to Run Quicker

To most of the world, Nicholas Thompson is named an editor, an AI fanatic, or one thing of a LinkedIn…

3 Min Read
Madisony

We cover the stories that shape the world, from breaking global headlines to the insights behind them. Our mission is simple: deliver news you can rely on, fast and fact-checked.

Recent News

The Finest Amazon System and Kindle Black Friday Offers (2025): Paperwhite, Scribe, Echo Dot Max
The Finest Amazon System and Kindle Black Friday Offers (2025): Paperwhite, Scribe, Echo Dot Max
November 29, 2025
MTRCB bans biblical horror ‘The Carpenter’s Son’ from public screening
MTRCB bans biblical horror ‘The Carpenter’s Son’ from public screening
November 29, 2025
GOOG Inventory Soars To All Time Highs on NVDA Chip Comparision
GOOG Inventory Soars To All Time Highs on NVDA Chip Comparision
November 29, 2025

Trending News

The Finest Amazon System and Kindle Black Friday Offers (2025): Paperwhite, Scribe, Echo Dot Max
MTRCB bans biblical horror ‘The Carpenter’s Son’ from public screening
GOOG Inventory Soars To All Time Highs on NVDA Chip Comparision
Ohio State vs. Michigan prediction, odds: “The Recreation” 2025 picks from confirmed mannequin
Southern Lebanon villages missed by Pope’s go to : NPR
  • About Us
  • Privacy Policy
  • Terms Of Service
Reading: A New Assault Lets Hackers Steal 2-Issue Authentication Codes From Android Telephones
Share

2025 © Madisony.com. All Rights Reserved.

Welcome Back!

Sign in to your account

Username or Email Address
Password

Lost your password?