Tag

Acropalypse

All articles tagged with #acropalypse

technology2 years ago

Microsoft addresses privacy and security issues in Windows Snipping Tool.

Microsoft released an emergency security update for Windows 10 and Windows 11 Snipping Tool to fix the Acropalypse privacy vulnerability. The vulnerability is caused by image editors not properly removing cropped image data when overwriting the original file. Microsoft has released security updates for both the Windows 10 Snip & Sketch and Windows 11 Snipping Tool program to resolve the Acropalypse flaw. The vulnerability is classified as "Low" severity because it "requires uncommon user interaction and several factors outside of an attacker's control." To install the security updates, open the Microsoft Store and go to Libary > Get Updates, and the latest version of the Windows Snipping Tool will be automatically installed.

technology2 years ago

Windows 11 Snipping Tool Bugs Fixed by Microsoft

Microsoft has released an updated version of the Windows 11 Snipping Tool that fixes the 'Acropalypse' privacy flaw, which allows the partial restoration of cropped images. The flaw was also found in the Windows 10 Snipping Tool, but no update is available yet. The vulnerability was first disclosed for Google Pixel devices and was fixed as part of the March security updates. The bug is caused by different reasons in Windows Snipping Tool and Google Pixel's Markup Tool, but the end result is the same: cropped-out data is not removed from the file when saving changes to the original file.

cybersecurity2 years ago

"Google Pixel's Markup Tool Vulnerability Exposes Redacted Images"

A vulnerability in Google Pixel's built-in Markup tool, dubbed "Acropalypse," allowed partially recovered edited or redacted images, including those that have been cropped or had their contents masked, for the past five years. The flaw was discovered by security researchers who reported it to Google in January 2023, and the company fixed it via an update released on March 13, 2023. However, any images shared in the past five years are vulnerable to the Acropalypse attack, and nothing can be done to remediate this. The vulnerability could expose sensitive information that the image creator redacted using Pixel’s Markup tool before sharing the media with others or posting it online.

technology2 years ago

"Pixel phones' Markup tool poses serious security risk"

A security flaw in the Markup tool on Pixel phones, dubbed "Acropalypse," allows hackers to un-redact and uncrop edited screenshots, potentially revealing sensitive information. The vulnerability has been fixed with the March 2023 security update, but screenshots shared before that remain vulnerable. The flaw can be exploited only if the original screenshot file is shared, and messaging and social media apps that compress and re-process shared images are not vulnerable. A technical demo has been devised to check if edited screenshots can be un-redacted.