Close Menu
Best in TechnologyBest in Technology
  • News
  • Phones
  • Laptops
  • Gadgets
  • Gaming
  • AI
  • Tips
  • More
    • Web Stories
    • Global
    • Press Release

Subscribe to Updates

Get the latest tech news and updates directly to your inbox.

What's On
All of My Employees Are AI Agents, and So Are My Executives

All of My Employees Are AI Agents, and So Are My Executives

12 November 2025
This Is the Platform Google Claims Is Behind a ‘Staggering’ Scam Text Operation

This Is the Platform Google Claims Is Behind a ‘Staggering’ Scam Text Operation

12 November 2025
BlazBlue Entropy Effect X Is Coming In February

BlazBlue Entropy Effect X Is Coming In February

12 November 2025
Facebook X (Twitter) Instagram
Just In
  • All of My Employees Are AI Agents, and So Are My Executives
  • This Is the Platform Google Claims Is Behind a ‘Staggering’ Scam Text Operation
  • BlazBlue Entropy Effect X Is Coming In February
  • Marvel Tōkon: Fighting Souls Adds X-Mansion Stage, Another Closed Beta In Early December
  • Elden Ring Nightreign Is Getting The Forsaken Hollows DLC In December
  • The Nike x Hyperice Hyperboot Is $200 Off
  • ‘The Running Man’ Conjures a Dystopian Vision of America That’s Still Not as Bad as Reality
  • Mixtape, The ’90s Coming-Of-Age Adventure By The Creators Of The Artful Escape, Delayed To 2026
Facebook X (Twitter) Instagram Pinterest Vimeo
Best in TechnologyBest in Technology
  • News
  • Phones
  • Laptops
  • Gadgets
  • Gaming
  • AI
  • Tips
  • More
    • Web Stories
    • Global
    • Press Release
Subscribe
Best in TechnologyBest in Technology
Home » A New Attack Lets Hackers Steal 2-Factor Authentication Codes From Android Phones
News

A New Attack Lets Hackers Steal 2-Factor Authentication Codes From Android Phones

News RoomBy News Room15 October 20252 Mins Read
Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
A New Attack Lets Hackers Steal 2-Factor Authentication Codes From Android Phones
Share
Facebook Twitter LinkedIn Pinterest Email

Android devices are vulnerable to a new attack that can covertly steal two-factor authentication codes, location timelines, and other private data in less than 30 seconds.

The new attack, named Pixnapping by the team of academic researchers who devised it, requires a victim to first install a malicious app on an Android phone or tablet. The app, which requires no system permissions, can then effectively read data that any other installed app displays on the screen. Pixnapping has been demonstrated on Google Pixel phones and the Samsung Galaxy S25 phone and likely could be modified to work on other models with additional work. Google released mitigations last month, but the researchers said a modified version of the attack works even when the update is installed.

Like Taking a Screenshot

Pixnapping attacks begin with the malicious app invoking Android programming interfaces that cause the authenticator or other targeted apps to send sensitive information to the device screen. The malicious app then runs graphical operations on individual pixels of interest to the attacker. Pixnapping then exploits a side channel that allows the malicious app to map the pixels at those coordinates to letters, numbers, or shapes.

“Anything that is visible when the target app is opened can be stolen by the malicious app using Pixnapping,” the researchers wrote on an informational website. “Chat messages, 2FA codes, email messages, etc. are all vulnerable since they are visible. If an app has secret information that is not visible (e.g., it has a secret key that is stored but never shown on the screen), that information cannot be stolen by Pixnapping.”

The new attack class is reminiscent of GPU.zip, a 2023 attack that allowed malicious websites to read the usernames, passwords, and other sensitive visual data displayed by other websites. It worked by exploiting side channels found in GPUs from all major suppliers. The vulnerabilities that GPU.zip exploited have never been fixed. Instead, the attack was blocked in browsers by limiting their ability to open iframes, an HTML element that allows one website (in the case of GPU.zip, a malicious one) to embed the contents of a site from a different domain.

Pixnapping targets the same side channel as GPU.zip, specifically the precise amount of time it takes for a given frame to be rendered on the screen.

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Previous ArticleA Quarter of the CDC Is Gone
Next Article Mark Cuban Would Still Have Dinner With Donald Trump

Related Articles

All of My Employees Are AI Agents, and So Are My Executives
News

All of My Employees Are AI Agents, and So Are My Executives

12 November 2025
This Is the Platform Google Claims Is Behind a ‘Staggering’ Scam Text Operation
News

This Is the Platform Google Claims Is Behind a ‘Staggering’ Scam Text Operation

12 November 2025
The Nike x Hyperice Hyperboot Is 0 Off
News

The Nike x Hyperice Hyperboot Is $200 Off

11 November 2025
‘The Running Man’ Conjures a Dystopian Vision of America That’s Still Not as Bad as Reality
News

‘The Running Man’ Conjures a Dystopian Vision of America That’s Still Not as Bad as Reality

11 November 2025
This Beats Pill Bluetooth Speaker Has Upgraded Features, and It’s Just 0
News

This Beats Pill Bluetooth Speaker Has Upgraded Features, and It’s Just $100

11 November 2025
This DOGE Whistleblower Is Running for Office
News

This DOGE Whistleblower Is Running for Office

11 November 2025
Demo
Top Articles
ChatGPT o1 vs. o1-mini vs. 4o: Which should you use?

ChatGPT o1 vs. o1-mini vs. 4o: Which should you use?

15 December 2024107 Views
Costco partners with Electric Era to bring back EV charging in the U.S.

Costco partners with Electric Era to bring back EV charging in the U.S.

28 October 202495 Views
5 laptops to buy instead of the M4 MacBook Pro

5 laptops to buy instead of the M4 MacBook Pro

17 November 202494 Views

Subscribe to Updates

Get the latest tech news and updates directly to your inbox.

Latest News
The Nike x Hyperice Hyperboot Is 0 Off News

The Nike x Hyperice Hyperboot Is $200 Off

News Room11 November 2025
‘The Running Man’ Conjures a Dystopian Vision of America That’s Still Not as Bad as Reality News

‘The Running Man’ Conjures a Dystopian Vision of America That’s Still Not as Bad as Reality

News Room11 November 2025
Mixtape, The ’90s Coming-Of-Age Adventure By The Creators Of The Artful Escape, Delayed To 2026 Gaming

Mixtape, The ’90s Coming-Of-Age Adventure By The Creators Of The Artful Escape, Delayed To 2026

News Room11 November 2025
Most Popular
The Spectacular Burnout of a Solar Panel Salesman

The Spectacular Burnout of a Solar Panel Salesman

13 January 2025135 Views
ChatGPT o1 vs. o1-mini vs. 4o: Which should you use?

ChatGPT o1 vs. o1-mini vs. 4o: Which should you use?

15 December 2024107 Views
Costco partners with Electric Era to bring back EV charging in the U.S.

Costco partners with Electric Era to bring back EV charging in the U.S.

28 October 202495 Views
Our Picks
Marvel Tōkon: Fighting Souls Adds X-Mansion Stage, Another Closed Beta In Early December

Marvel Tōkon: Fighting Souls Adds X-Mansion Stage, Another Closed Beta In Early December

12 November 2025
Elden Ring Nightreign Is Getting The Forsaken Hollows DLC In December

Elden Ring Nightreign Is Getting The Forsaken Hollows DLC In December

12 November 2025
The Nike x Hyperice Hyperboot Is 0 Off

The Nike x Hyperice Hyperboot Is $200 Off

11 November 2025

Subscribe to Updates

Get the latest tech news and updates directly to your inbox.

Facebook X (Twitter) Instagram Pinterest
  • Privacy Policy
  • Terms of use
  • Advertise
  • Contact Us
© 2025 Best in Technology. All Rights Reserved.

Type above and press Enter to search. Press Esc to cancel.