Close Menu
AdimorahBlogAdimorahBlog
  • Home
  • ABOUT US
  • CONTACT US
  • PRIVACY POLICY
  • XIAOMI
    • Xiaomi apps
    • Xiaomi News
    • Xiaomi Pad
    • Redmi
    • POCO
    • POCO beta testers
  • MIUI updates
    • MIUI 14
    • MIUI beta testers
    • MIUI launcher
  • Google
    • Google Camera
    • Pixel
    • Google chrome
  • Samsung
    • OneUI news
    • Samsung News
    • Samsung Galaxy Watch
  • Android
    • Android 13
    • Android 14
    • Android 15
    • Android Auto
  • Smartphone
    • Apple
    • Samsung
    • Pixel
    • XIAOMI
    • Redmi
    • POCO
    • OnePlus
    • Sony
    • Fairphone
    • OnePlus
  • How To
  • Gaming
    • Video gaming
Facebook X (Twitter) Instagram
Facebook X (Twitter) Instagram
AdimorahBlogAdimorahBlog
Subscribe
  • Home
  • ABOUT US
  • CONTACT US
  • PRIVACY POLICY
  • XIAOMI
    • Xiaomi apps
    • Xiaomi News
    • Xiaomi Pad
    • Redmi
    • POCO
    • POCO beta testers
  • MIUI updates
    • MIUI 14
    • MIUI beta testers
    • MIUI launcher
  • Google
    • Google Camera
    • Pixel
    • Google chrome
  • Samsung
    • OneUI news
    • Samsung News
    • Samsung Galaxy Watch
  • Android
    • Android 13
    • Android 14
    • Android 15
    • Android Auto
  • Smartphone
    • Apple
    • Samsung
    • Pixel
    • XIAOMI
    • Redmi
    • POCO
    • OnePlus
    • Sony
    • Fairphone
    • OnePlus
  • How To
  • Gaming
    • Video gaming
AdimorahBlogAdimorahBlog
Home | MIUI update | Xiaomi News | Google | The Pixel Markup screenshot vulnerability addressed with Android QPR2 update 
Google

The Pixel Markup screenshot vulnerability addressed with Android QPR2 update 

Onyebuchi UcheBy Onyebuchi UcheMarch 20, 2023No Comments2 Mins Read
Facebook Twitter Pinterest LinkedIn Tumblr Email
front of the Google Pixel 7 Pro
Share
Facebook Twitter LinkedIn Pinterest Email

Apart from the Samsung Exynos modem problem, the March 2023 security update for Android 13 QPR2 patches the Pixel Markup screenshot vulnerability as well. Simon Aarons discovered and submitted this vulnerability (CVE-2023-21036) to Google in early January, with David Buchanan developing the initial proof-of-concept exploit:

Pixel Markup screenshot vulnerability

“Screenshots cropped using the built-in “Markup” app on Google Pixel devices may be retroactively un-cropped and un-redacted under any circumstances.” For reference, the built-in Markup feature on Pixel phones, which debuted with Android 9 Pie in 2018, allows you to modify screenshots (crop, add text, draw, and highlight).

advertisement

The Pixel Markup screenshot vulnerability 

Let’s imagine you submit a screenshot from a hypothetical bank app/website that contains a photo of your credit/debit card. Everything but the card is cropped out, and the 16-digit number is blacked out with Markup’s Pen tool. You then distribute the message using a service such as Discord.

Because of a flaw in the way Markup works, anybody who downloads the picture can do a “partial recovery of the original, unaltered image data of [the] cropped and/or censored screenshot.” A malevolent party may erase the black lines and view the credit card number, as well as 80% of the whole screenshot, which may contain additional sensitive information, in the example above.

“The top 20% of the image is corrupted, but the remainder of the image- including a photo of the credit card with its number visible – is fully recovered.” The Pixel Markup screenshot vulnerability may be an issue for you if you shared screenshots with addresses, phone numbers, or other sensitive information.

Pixel Markup screenshot vulnerability

“The privacy impact of this bug stems from people sharing cropped images [that] unknowingly included extra data. Fortunately, most social media services re-process uploaded images, which strips the trailing data and mitigates the vulnerability. For example, Twitter is safe from acropalypse. The following is an incomplete list of known vulnerable services and apps commonly used to share images: (i.e. services that do not strip trailing image data)”

Well, it’s nice the Pixel Markup screenshot vulnerability was fixed with the March 2023 security patch, with CVE-2023-21036 listed as having a “High” severity. That Pixel update is currently available for the Pixel 4a-5a, 7, and 7 Pro.

Source. 

Google Pixels March 2023 security patch Pixel Markup
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Onyebuchi Uche

Related Posts

Android Auto 14.4 stable update is now available for download

May 18, 2025

Google confirms the stable Android 16 release date

May 13, 2025

Android Auto 14.4 beta update is now available for download

May 10, 2025
Add A Comment
Leave A Reply

Recent Posts
  • Android Auto 14.4 stable update is now available for download
  • Qualcomm Snapdragon 7 Gen 4: Snapdragon 7 Gen 4 Phones
  • Samsung Galaxy A54 One UI 7 stable update is now available
  • Google confirms the stable Android 16 release date
  • Samsung One UI 8 beta public preview will start this month
About Us
AdimorahBlog was founded in 2017 and has grown into a global brand in the past years. As we continue to expand, we will keep providing our readers with the best coverage on Xiaomi HyperOS updates and smartphone latest Android OS updates. We strive to become the update hub for all smartphones. Contact Us: info@adimorahblog.com
AdimorahBlog
Facebook X (Twitter) YouTube Telegram
  • Home
  • CONTACT US
  • ABOUT US
  • PRIVACY POLICY
© 2025 AdimorahBlog. Designed by ThemeSphere.

Type above and press Enter to search. Press Esc to cancel.