9to5 Google: Pixel Markup vulnerability lets some screenshots be un-redacted, un-cropped; fixed by March update

9to5 Google: Pixel Markup vulnerability lets some screenshots be un-redacted, un-cropped; fixed by March update. “For example (as shared on Twitter), let’s say you upload a screenshot from a hypothetical bank app/website that includes a picture of your credit/debit card. You crop out everything save for the card and then use Markup’s Pen tool to black out the 16-digit number. You then share that message on a service, like Discord. Given a vulnerability in how Markup works, somebody that downloads the image is able to perform a ‘partial recovery of the original, unedited image data of [the] cropped and/or redacted screenshot.'”

Leave a Reply

%d bloggers like this: