Back to News
Market Impact: 0.7

New Pixnapping Android Flaw Lets Rogue Apps Steal 2FA Codes Without Permissions

GOOGGOOGL
Technology & InnovationCybersecurity & Data Privacy
New Pixnapping Android Flaw Lets Rogue Apps Steal 2FA Codes Without Permissions

Researchers have uncovered "Pixnapping," a new side-channel attack impacting Android devices, including Google and Samsung models, capable of covertly stealing sensitive data such as two-factor authentication codes and Google Maps timelines. This vulnerability, tracked as CVE-2025-48561, exploits Android APIs and a hardware side-channel (GPU.zip), allowing malicious apps to extract data without special permissions, posing significant data security risks. Although Google issued a patch in its September 2025 Android Security Bulletin, a workaround has emerged, and a related app list bypass vulnerability remains unpatched, marked by Google as "won't fix," underscoring persistent security challenges for the Android ecosystem and potential implications for user trust and platform integrity.

Analysis

Researchers have identified "Pixnapping," a novel side-channel attack capable of covertly stealing sensitive data, including two-factor authentication codes and Google Maps timelines, from Android devices. This vulnerability, affecting Google and Samsung models running Android 13-16, leverages Android APIs and the GPU.zip hardware side-channel to allow malicious apps to capture 2FA codes in under 30 seconds without requiring special permissions. The underlying methodology is present across all Android devices, posing a broad platform risk. Google has acknowledged the issue, tracking it as CVE-2025-48561 with a CVSS score of 5.5, and released patches in its September 2025 Android Security Bulletin. However, a workaround has already emerged, re-enabling Pixnapping, which Google is reportedly addressing. More critically, a related app list bypass vulnerability, which circumvents Android 11 restrictions on querying installed apps, remains unpatched and has been marked "won't fix" by Google. This persistent security flaw, particularly the "won't fix" stance on the app list bypass, contributes to an "extremely negative" sentiment (-0.8) surrounding Google's platform security and carries a significant market impact score of 0.7. The ease with which any app can exploit Pixnapping, once installed, underscores potential risks to user data privacy and trust in the Android ecosystem, impacting GOOG/GOOGL's brand and long-term platform integrity.

AllMind AI Terminal

AI-powered research, real-time alerts, and portfolio analytics for institutional investors.

Request a Demo

Market Sentiment

Overall Sentiment

extremely negative

Sentiment Score

-0.80

Ticker Sentiment

GOOG-0.80
GOOGL-0.80

Key Decisions for Investors

  • Monitor Google's progress on the Pixnapping workaround fix and the long-term implications of the "won't fix" app list bypass for Android's security posture and user trust.
  • Assess potential reputational and regulatory risks for Google (GOOG/GOOGL) stemming from persistent, unpatched vulnerabilities that compromise user data and privacy.
  • Evaluate the broader cybersecurity landscape for mobile platforms, considering this incident as a signal of evolving side-channel attack sophistication and the need for robust, proactive security investments.