CVE-2025-48561
NixOS vulnerability analysis and mitigation

Overview

CVE-2025-48561 is a side-channel information disclosure vulnerability in Android's display/graphics subsystem (frameworks/native), publicly dubbed "Pixnapping." It affects Android versions 13.0, 14.0, 15.0, and 16.0, and allows a local attacker to access data displayed on the screen — including 2FA codes, Signal messages, and other sensitive on-screen content — without any additional execution privileges or user interaction. The vulnerability was disclosed as part of Google's September 2025 Android Security Bulletin (published September 2, 2025) and received significant public attention in October 2025 when researchers published detailed attack methodology. It carries a CVSS v3.1 base score of 5.5 (Medium) (Android Bulletin, Feedly).

Technical details

The vulnerability is classified as CWE-203 (Observable Discrepancy), a side-channel weakness in which differences in system behavior leak information to an unprivileged observer. Specifically, the flaw exists in multiple locations within Android's frameworks/native layer, where screen pixel data can be inferred or directly accessed by a local application without requiring the READ_FRAME_BUFFER or screenshot permissions. The attack technique — named Pixnapping by researchers at Carnegie Mellon University's CyLab — exploits timing or rendering discrepancies to reconstruct on-screen content pixel by pixel, enabling theft of displayed secrets such as TOTP codes from Google Authenticator within approximately 30 seconds. The patch is available in the Android source repository targeting platform/frameworks/native (Android Bulletin, Android Source, CyLab CMU).

Impact

Successful exploitation allows a local, unprivileged application to silently read sensitive data rendered on the Android screen — including 2FA/MFA codes, private messages (e.g., Signal), crypto wallet seed phrases, and other confidential information — without triggering any permission prompts or requiring user interaction. The attack is purely a confidentiality breach (no integrity or availability impact), but the data exposed can enable account takeover, financial theft, and further compromise of downstream services. Confirmed affected devices include Google Pixel and Samsung Galaxy smartphones running Android 13–16 (The Hacker News, Bleeping Computer, CyLab CMU).

Exploitation steps

  1. Develop or deploy a malicious app: Create or distribute an Android application that requests no sensitive permissions (no READ_FRAME_BUFFER, no screenshot access), making it appear benign to users and app store reviewers.
  2. Install on target device: Convince the victim to install the app via sideloading or a third-party store on an Android 13–16 device (e.g., Pixel or Samsung Galaxy).
  3. Trigger side-channel observation: Once running in the foreground or background, the malicious app exploits the observable discrepancy in frameworks/native rendering behavior to probe pixel values of the screen without permission.
  4. Reconstruct on-screen content: Using the side-channel signal, the app reconstructs displayed content pixel by pixel — researchers demonstrated full 2FA code extraction from Google Authenticator in under 30 seconds.
  5. Exfiltrate captured data: The reconstructed screen data (TOTP codes, messages, seed phrases) is transmitted to an attacker-controlled server, enabling account takeover or financial theft (CyLab CMU, Bleeping Computer, The Hacker News).

Indicators of compromise

  • Process/App Behavior: Installed applications with no declared sensitive permissions (no READ_FRAME_BUFFER, no CAPTURE_VIDEO_OUTPUT) that exhibit high CPU or GPU usage while running in the background, particularly when sensitive apps (authenticators, messaging apps) are in the foreground.
  • Network: Unexpected outbound network connections from low-privilege apps to unknown external IPs or domains, especially shortly after a user views 2FA codes or sensitive messages.
  • Logs: Android system logs (logcat) showing unusual rendering or SurfaceFlinger interactions from third-party apps; anomalous access patterns to display-related system services.
  • File System: Presence of apps with no declared screenshot/screen-capture permissions that write encoded data to external storage or initiate network uploads after screen activity (Malwarebytes, Bleeping Computer).

Mitigation and workarounds

Google addressed CVE-2025-48561 in the September 2025 Android Security Bulletin (patch level 2025-09-01); users should apply the September 2025 (or later) security patch immediately. Samsung and Huawei have also incorporated the fix in their respective September and November 2025 security updates. As a workaround prior to patching, users should avoid displaying sensitive information (2FA codes, seed phrases, private messages) while untrusted apps are installed, restrict sideloading of apps from unknown sources, and use hardware security keys instead of TOTP-based 2FA where possible. Google indicated a further fix was planned for the December 2025 update to address residual attack surface (Android Bulletin, 9to5Google, Android Source).

Community reactions

The Pixnapping vulnerability generated significant media and community attention in October 2025 when CMU CyLab researchers published their findings alongside a dedicated website. Coverage spanned major outlets including The Register, ZDNet, Bleeping Computer, PCMag, The Hacker News, and Bitdefender, with widespread concern about the zero-permission nature of the attack. Security researchers on Mastodon and Reddit (including the GrapheneOS community) discussed implications for privacy-focused Android distributions. Kaspersky published a dedicated blog post explaining the attack to consumers. The crypto community raised particular alarm given the potential to steal seed phrases and private keys displayed on screen (The Hacker News, Bleeping Computer, Kaspersky Blog, CyLab CMU).

Additional resources


SourceThis report was generated using AI

Related NixOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-66033HIGH8.7
  • NixOS logoNixOS
  • seal-libssh2
NoYesJul 24, 2026
CVE-2026-66035HIGH7.7
  • NixOS logoNixOS
  • libssh2-devel
NoYesJul 24, 2026
CVE-2026-66034HIGH7.7
  • NixOS logoNixOS
  • libssh2
NoYesJul 24, 2026
CVE-2026-45816HIGH7.5
  • NixOS logoNixOS
  • nimble
NoYesJul 24, 2026
CVE-2026-46452MEDIUM5.3
  • NixOS logoNixOS
  • nimble
NoYesJul 24, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management