
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-48561 is a side-channel information disclosure vulnerability in Android's display/graphics subsystem (frameworks/native), publicly dubbed "Pixnapping." It affects Android versions 13.0, 14.0, 15.0, and 16.0, and allows a local attacker to access data displayed on the screen — including 2FA codes, Signal messages, and other sensitive on-screen content — without any additional execution privileges or user interaction. The vulnerability was disclosed as part of Google's September 2025 Android Security Bulletin (published September 2, 2025) and received significant public attention in October 2025 when researchers published detailed attack methodology. It carries a CVSS v3.1 base score of 5.5 (Medium) (Android Bulletin, Feedly).
The vulnerability is classified as CWE-203 (Observable Discrepancy), a side-channel weakness in which differences in system behavior leak information to an unprivileged observer. Specifically, the flaw exists in multiple locations within Android's frameworks/native layer, where screen pixel data can be inferred or directly accessed by a local application without requiring the READ_FRAME_BUFFER or screenshot permissions. The attack technique — named Pixnapping by researchers at Carnegie Mellon University's CyLab — exploits timing or rendering discrepancies to reconstruct on-screen content pixel by pixel, enabling theft of displayed secrets such as TOTP codes from Google Authenticator within approximately 30 seconds. The patch is available in the Android source repository targeting platform/frameworks/native (Android Bulletin, Android Source, CyLab CMU).
Successful exploitation allows a local, unprivileged application to silently read sensitive data rendered on the Android screen — including 2FA/MFA codes, private messages (e.g., Signal), crypto wallet seed phrases, and other confidential information — without triggering any permission prompts or requiring user interaction. The attack is purely a confidentiality breach (no integrity or availability impact), but the data exposed can enable account takeover, financial theft, and further compromise of downstream services. Confirmed affected devices include Google Pixel and Samsung Galaxy smartphones running Android 13–16 (The Hacker News, Bleeping Computer, CyLab CMU).
READ_FRAME_BUFFER, no screenshot access), making it appear benign to users and app store reviewers.frameworks/native rendering behavior to probe pixel values of the screen without permission.READ_FRAME_BUFFER, no CAPTURE_VIDEO_OUTPUT) that exhibit high CPU or GPU usage while running in the background, particularly when sensitive apps (authenticators, messaging apps) are in the foreground.logcat) showing unusual rendering or SurfaceFlinger interactions from third-party apps; anomalous access patterns to display-related system services.Google addressed CVE-2025-48561 in the September 2025 Android Security Bulletin (patch level 2025-09-01); users should apply the September 2025 (or later) security patch immediately. Samsung and Huawei have also incorporated the fix in their respective September and November 2025 security updates. As a workaround prior to patching, users should avoid displaying sensitive information (2FA codes, seed phrases, private messages) while untrusted apps are installed, restrict sideloading of apps from unknown sources, and use hardware security keys instead of TOTP-based 2FA where possible. Google indicated a further fix was planned for the December 2025 update to address residual attack surface (Android Bulletin, 9to5Google, Android Source).
The Pixnapping vulnerability generated significant media and community attention in October 2025 when CMU CyLab researchers published their findings alongside a dedicated website. Coverage spanned major outlets including The Register, ZDNet, Bleeping Computer, PCMag, The Hacker News, and Bitdefender, with widespread concern about the zero-permission nature of the attack. Security researchers on Mastodon and Reddit (including the GrapheneOS community) discussed implications for privacy-focused Android distributions. Kaspersky published a dedicated blog post explaining the attack to consumers. The crypto community raised particular alarm given the potential to steal seed phrases and private keys displayed on screen (The Hacker News, Bleeping Computer, Kaspersky Blog, CyLab CMU).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."