What you need to know
- A security vulnerability called “aCropalypse” could pose a significant data risk to Pixels, custom ROMs, and other Android devices using the default “markup” editing tool.
- Pixel PNG screenshots can be decrypted by attackers and rediscover sensitive information you don’t want others to see.
- Fortunately, this vulnerability has been fixed by Google’s recent feature removal in March.
Simple and easy things like editing screenshots from Pixel are cause for concern. Dubbed “aCropalypse,” researchers Simon Aarons and David Buchanan discovered an exploit for PNG screenshots after cropping pixels using markup (via Android Police). The issue has been confirmed to affect Pixel, his non-Pixel Android smartphones, as well as some custom ROMs, and while it’s not limited to his Discord on the messaging service, it’s fairly prevalent. I’m here.
Both researchers discovered a serious security flaw on January 2nd and quickly worked out ways to prove its existence before alerting Google on the same day.After acknowledging that, Google patched the issue first It was released on January 24th, but the fix wasn’t deployed until almost two months later, when the March feature was removed.
The technical exploit apparently dates back several years due to API changes from Android 10 uncovered by IssueTracker researchers. It is said that the markup tool has changed and no longer truncates (shortens) image files.
Simply put, if the original file size is 10 MB and after cropping it’s 3 MB, the markup tool won’t discard unwanted photos that sometimes hold very sensitive information. . As researcher Simon explained, “Basically, on the Pixel 7 Pro, when you crop and save a screenshot, it overwrites the image with the new version, but leaves the rest of the original file intact. .”

Buchanan posted some information on his blog about what a PNG file is and how it manipulates its blocks of data. PNG compresses data into blocks. If the file has been edited or trimmed, in this case one of the existing blocks may contain information from something that was removed (or obscured) by the editing process. Buchanan explains: in fact, Most images are not like this. ”
Discord is highlighted due to the way it previously handled user-uploaded images. Until January 17th, Discord did not remove metadata or compressed images in its own way. Because of this, exploits can be used with messaging services.
Both researchers provided screenshots taken from multiple Google devices, including a Pixel 7 Pro, to create a tool demonstrating this exploitation process.It can be very difficult to see in action, given the edits made to block out certain information and the fully cropped image being restored to its full original shape. people have chime in On Twitter, screenshots of themselves were shown to testers, revealing that scraps previously thought to be discarded aren’t really gone.
This problem didn’t seem to affect JPEG images. This may be because different file types handle data differently. However, the March update may still expose old edited PNG files that have been submitted.
Introducing acropalypse: A critical privacy vulnerability in Markup, Google Pixel’s built-in screenshot editing tool, allowing partial recovery of original, unedited image data for cropped and/or edited screenshots to Thanks to @David3141593 for all the help! pic.twitter.com/BXNQomnHbrMarch 17, 2023