{"id":215121,"date":"2025-10-15T11:38:07","date_gmt":"2025-10-15T11:38:07","guid":{"rendered":"https:\/\/www.newsbeep.com\/au\/215121\/"},"modified":"2025-10-15T11:38:07","modified_gmt":"2025-10-15T11:38:07","slug":"new-attack-alert-as-android-2fa-codes-stolen-in-30-seconds-flat","status":"publish","type":"post","link":"https:\/\/www.newsbeep.com\/au\/215121\/","title":{"rendered":"New Attack Alert As Android 2FA Codes Stolen In 30 Seconds Flat"},"content":{"rendered":"<p><img decoding=\"async\" class=\" top-image\" src=\"https:\/\/www.newsbeep.com\/au\/wp-content\/uploads\/2025\/10\/1760528287_434_960x0.jpg\" alt=\"The Android logo appears on the screen of a smartphone \" data-height=\"2876\" data-width=\"4315\" fetchpriority=\"high\" style=\"position:absolute;top:0\"\/><\/p>\n<p>New attack steals Android 2FA codes in 30 seconds flat.<\/p>\n<p>NurPhoto via Getty Images<\/p>\n<p>A stealthy new Android attack has been confirmed that can steal two-factor authentication codes in almost no time at all, just 30 seconds flat, in fact. Here\u2019s everything you need to know about the Pixnapping threat, including Google\u2019s response. Spoiler alert: you\u2019ll have to wait until December for Google to issue a security update.<\/p>\n<p>The Pixnapping Android Attack Threat \u2014 What You need To Know<\/p>\n<p>Following a collaboration between security researchers from the University of California, Berkeley, the University of Washington, University of California, San Diego and Carnegie Mellon University, it has been confirmed that certain Google Pixel and Samsung Galaxy smartphones can be hacked using a Pixnapping attack that gobbles up 2FA codes in less than 30 seconds. <\/p>\n<p>Although the researchers only tested the attack against specific Google Pixel and Samsung Galaxy phones, that doesn\u2019t mean you are safe if you use a different smartphone. \u201cThe core mechanisms enabling the attack are typically available in all Android devices,\u201d the <a class=\"color-link\" href=\"https:\/\/www.pixnapping.com\/\" target=\"_blank\" rel=\"nofollow noopener noreferrer\" data-ga-track=\"ExternalLink:https:\/\/www.pixnapping.com\/\" aria-label=\"researchers have warned\">researchers have warned<\/a>. <\/p>\n<p><a class=\"embed-base color-body color-body-border link-embed embed-1\" href=\"https:\/\/www.forbes.com\/sites\/daveywinder\/2025\/10\/05\/googles-new-gmail-security-update---encrypted-email-for-all\/\" target=\"_blank\" aria-label=\"Google Confirms Gmail Encryption Update \u2014 What You Need To Know\" data-ga-track=\"forbesEmbedly:https:\/\/www.forbes.com\/sites\/daveywinder\/2025\/10\/05\/googles-new-gmail-security-update---encrypted-email-for-all\/\" rel=\"nofollow noopener\">ForbesGoogle Confirms Gmail Encryption Update \u2014 What You Need To KnowBy Davey Winder<\/a><\/p>\n<p>So, what is Pixnapping? According to Christopher Fletcher, Pranav Gopalkrishnan, David Kohlbrenner, Riccardo Paccagnella, Hovav Shacham, Alan Wang and Yingchen Wang, the researchers behind the alert, Pixnapping induces \u201cgraphical operations on individual sensitive pixels rendered by the target app,\u201d an app such as, say, Google Authenticator, that are then stolen, one by one, using a side-channel process. In simple terms,   it effectively takes a screenshot without actually having to do so. Pixnapping targets the pixels in the part of the screen where Google Authenticator is known to render 2FA code responses, and meticulously recovers them to form the complete picture of your authentication code, in less than 30 seconds. <\/p>\n<p>What is most worrying is that a Pixnapping attack can be executed by any running Android app, the researchers warned, \u201ceven if it does not have any Android permissions.\u201d Things also look pretty bad when you consider that the Pixnapping <a class=\"color-link\" href=\"https:\/\/www.pixnapping.com\/pixnapping.pdf\" target=\"_blank\" rel=\"nofollow noopener noreferrer\" data-ga-track=\"ExternalLink:https:\/\/www.pixnapping.com\/pixnapping.pdf\" aria-label=\"research paper\">research paper<\/a> reveals that anything visible can be targeted by this attack, including chat and email messages.<\/p>\n<p>On the positive flipside, secret information that is not displayed cannot be exfiltrated by the pixnapping technique. And that\u2019s not where the good news stops either: this attack requires the installation of a malicious app in the first place.<\/p>\n<p>Which Android Devices Are At Risk?<\/p>\n<p>Although, as already mentioned, most any Android device could be impacted by a Pixnapping attack, the following smartphones were found to be vulnerable during the research:<\/p>\n<p>Google Pixel 6<br \/>Google Pixel 7<br \/>Google Pixel 8<br \/>Google Pixel 9<br \/>Samsung Galaxy S25<\/p>\n<p>The devices were running Android 13 to 16.<\/p>\n<p><a class=\"embed-base color-body color-body-border link-embed embed-2\" href=\"https:\/\/www.forbes.com\/sites\/daveywinder\/2025\/10\/03\/gmail-says-it-wont-deliver-insecure-email-from-january-2026\/\" target=\"_blank\" aria-label=\"Gmail Will Stop Supporting These Third-Party Emails From January 2026\" data-ga-track=\"forbesEmbedly:https:\/\/www.forbes.com\/sites\/daveywinder\/2025\/10\/03\/gmail-says-it-wont-deliver-insecure-email-from-january-2026\/\" rel=\"nofollow noopener\">ForbesGmail Will Stop Supporting These Third-Party Emails From January 2026By Davey Winder<\/a>Google Responds To Android Pixnapping Attack Threat<\/p>\n<p>A Google spokesperson, while stating that there have been no instances of Pixnapping evidenced as being exploited in the wild, confirmed that a September Android security patch for CVE-2025-48561 partially mitigates the impact of such an attack. \u201cWe are issuing an additional patch for this vulnerability in the December Android security bulletin,\u201d the Google spokesperson added. <\/p>\n","protected":false},"excerpt":{"rendered":"New attack steals Android 2FA codes in 30 seconds flat. NurPhoto via Getty Images A stealthy new Android&hellip;\n","protected":false},"author":2,"featured_media":215122,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[6],"tags":[131778,131779,131780,66820,64,63,113,28714,131781,105,110183],"class_list":["post-215121","post","type-post","status-publish","format-standard","has-post-thumbnail","category-technology","tag-2fa","tag-2fa-code","tag-android-2fa","tag-android-attack","tag-au","tag-australia","tag-google","tag-google-2fa","tag-pixnapping","tag-technology","tag-two-factor-authentication"],"_links":{"self":[{"href":"https:\/\/www.newsbeep.com\/au\/wp-json\/wp\/v2\/posts\/215121","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.newsbeep.com\/au\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.newsbeep.com\/au\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/au\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/au\/wp-json\/wp\/v2\/comments?post=215121"}],"version-history":[{"count":0,"href":"https:\/\/www.newsbeep.com\/au\/wp-json\/wp\/v2\/posts\/215121\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/au\/wp-json\/wp\/v2\/media\/215122"}],"wp:attachment":[{"href":"https:\/\/www.newsbeep.com\/au\/wp-json\/wp\/v2\/media?parent=215121"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.newsbeep.com\/au\/wp-json\/wp\/v2\/categories?post=215121"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.newsbeep.com\/au\/wp-json\/wp\/v2\/tags?post=215121"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}