Friday, December 5, 2025
This Big Influence
  • Home
  • World
  • Podcast
  • Politics
  • Business
  • Health
  • Tech
  • Awards
  • Shop
No Result
View All Result
This Big Influence
No Result
View All Result
Home Tech

A New Attack Lets Hackers Steal 2-Factor Authentication Codes From Android Phones

ohog5 by ohog5
October 14, 2025
in Tech
0
A New Attack Lets Hackers Steal 2-Factor Authentication Codes From Android Phones
74
SHARES
1.2k
VIEWS
Share on FacebookShare on Twitter


You might also like

“This Chat’s Kind of Dead. Anything Going On?”

New COVID vax formula produces antibodies nearly 3X longer

The Louisiana Department of Wildlife and Fisheries Is Detaining People for ICE

Android units are weak to a brand new assault that may covertly steal two-factor authentication codes, location timelines, and different non-public information in lower than 30 seconds.

The brand new assault, named Pixnapping by the workforce of educational researchers who devised it, requires a sufferer to first set up a malicious app on an Android telephone or pill. The app, which requires no system permissions, can then successfully learn information that every other put in app shows on the display screen. Pixnapping has been demonstrated on Google Pixel telephones and the Samsung Galaxy S25 telephone and sure could possibly be modified to work on different fashions with extra work. Google launched mitigations final month, however the researchers stated a modified model of the assault works even when the replace is put in.

Like Taking a Screenshot

Pixnapping assaults start with the malicious app invoking Android programming interfaces that trigger the authenticator or different focused apps to ship delicate data to the gadget display screen. The malicious app then runs graphical operations on particular person pixels of curiosity to the attacker. Pixnapping then exploits a side channel that permits the malicious app to map the pixels at these coordinates to letters, numbers, or shapes.

“Something that’s seen when the goal app is opened will be stolen by the malicious app utilizing Pixnapping,” the researchers wrote on an informational website. “Chat messages, 2FA codes, electronic mail messages, and so on. are all weak since they’re seen. If an app has secret data that’s not seen (e.g., it has a secret key that’s saved however by no means proven on the display screen), that data can’t be stolen by Pixnapping.”

The brand new assault class is harking back to GPU.zip, a 2023 assault that allowed malicious web sites to learn the usernames, passwords, and different delicate visible information displayed by different web sites. It labored by exploiting aspect channels present in GPUs from all main suppliers. The vulnerabilities that GPU.zip exploited have by no means been fastened. As a substitute, the assault was blocked in browsers by limiting their capacity to open iframes, an HTML factor that permits one web site (within the case of GPU.zip, a malicious one) to embed the contents of a web site from a unique area.

Pixnapping targets the identical aspect channel as GPU.zip, particularly the exact period of time it takes for a given body to be rendered on the display screen.



Source link

Tags: 2FactorAndroidAttackAuthenticationCodesHackersLetsphonesSteal
Share30Tweet19
ohog5

ohog5

Recommended For You

“This Chat’s Kind of Dead. Anything Going On?”

by ohog5
December 5, 2025
0
“This Chat’s Kind of Dead. Anything Going On?”

Kevin Dietsch / Getty Photos Because the nation reels over Pete Hegseth allegedly giving direct orders to hold out heinous battle crimes, we are actually being reminded of...

Read more

New COVID vax formula produces antibodies nearly 3X longer

by ohog5
December 5, 2025
0
New COVID vax formula produces antibodies nearly 3X longer

Share this Article You're free to share this text below the Attribution 4.0 Worldwide license. Within the battle in opposition to COVID-19, accountable for greater than 1.2 million...

Read more

The Louisiana Department of Wildlife and Fisheries Is Detaining People for ICE

by ohog5
December 4, 2025
0
The Louisiana Department of Wildlife and Fisheries Is Detaining People for ICE

The Louisiana Division Of Wildlife And Fisheries (LDWF), sometimes accountable partially for overseeing wildlife reserves and imposing native looking guidelines, has assisted United States immigration authorities with bringing...

Read more

Cyber Monday video doorbell deal: Save 57% on Blink video doorbell, a Mashable Readers’ Choice Award winner

by ohog5
December 4, 2025
0
Cyber Monday video doorbell deal: Save 57% on Blink video doorbell, a Mashable Readers’ Choice Award winner

Save $40: The Blink video doorbell is presently on sale for $29.99 over at Amazon. That’s $40 off its common value or 57% off. Cyber Monday is right...

Read more

New Algorithm Lets Architects Design Stunning Curved Structures in Minutes

by ohog5
December 3, 2025
0
New Algorithm Lets Architects Design Stunning Curved Structures in Minutes

A brand new NURBS-based algorithm is revolutionizing gridshell design by enabling sooner, smoother, and extra versatile shape-finding. What as soon as required 90 hours of GPU time now...

Read more
Next Post
Trump to roll out sweeping new tariffs – CNN

Michigan Cheese and Dairy Guild Initiated with Assistance from MDARD Program - State of Michigan (.gov)

Related News

Team links concussions to suicidal thoughts in high school athletes

Team links concussions to suicidal thoughts in high school athletes

November 17, 2023
No, AI Doesn’t Mean Human-Made Music Is Doomed. Here’s Why.

No, AI Doesn’t Mean Human-Made Music Is Doomed. Here’s Why.

June 22, 2024
Scientists Just Found a Smarter Way to Beat UTIs

Scientists Just Found a Smarter Way to Beat UTIs

March 16, 2025

Browse by Category

  • Business
  • Health
  • Politics
  • Tech
  • World

Recent News

“This Chat’s Kind of Dead. Anything Going On?”

“This Chat’s Kind of Dead. Anything Going On?”

December 5, 2025
Trump to roll out sweeping new tariffs – CNN

World Cup 2026 draw live updates: Latest news and everything you need to know about today’s ceremony – The Athletic – The New York Times

December 5, 2025

CATEGORIES

  • Business
  • Health
  • Politics
  • Tech
  • World

Follow Us

Recommended

  • “This Chat’s Kind of Dead. Anything Going On?”
  • World Cup 2026 draw live updates: Latest news and everything you need to know about today’s ceremony – The Athletic – The New York Times
  • DHS Announces Arrests as Immigration Operation Underway in Minneapolis
  • N.C. Chamber, BCBS launch small business health plan – The Daily News – Jacksonville, NC
No Result
View All Result
  • Home
  • World
  • Podcast
  • Politics
  • Business
  • Health
  • Tech
  • Awards
  • Shop

© 2023 ThisBigInfluence

Cleantalk Pixel
Are you sure want to unlock this post?
Unlock left : 0
Are you sure want to cancel subscription?