Security researchers have exposed a serious Android vulnerability called Pixnapping that allows hackers to steal sensitive information from your phone without needing any permissions.
This attack can capture 2FA codes, private messages, and other confidential data directly from your screen.

What Is Pixnapping?
A team from UC Berkeley, University of Washington, and Carnegie Mellon discovered this attack method that works on Android versions 13 through 16. The researchers tested it successfully on Google Pixel 6-9 and Samsung Galaxy S25 devices.
The scary part? Any app can launch this attack without requesting a single permission. That means a seemingly harmless app could be stealing your data right now.
Researchers demonstrated the attack against popular apps like Gmail, Signal, Google Authenticator, and Venmo. They were able to steal 2FA codes in under 30 seconds while keeping the entire process hidden from users.

How Does This Android Attack Work?
The attack happens when you open a malicious app on your device. Behind the scenes, that app quietly launches your authenticator or another target app. Then it begins capturing your screen one pixel at a time.

The malicious app uses Android intents, a normal feature that lets apps communicate, to display sensitive information from other apps. It then applies blur effects to individual pixels and measures how long each pixel takes to render.
Different colors take different amounts of time to process, allowing the attacker to determine what’s displayed on your screen.
Hide Your Digital Fingerprint
This process is slow, capturing only 0.6 to 2.1 pixels per second. However, that’s fast enough to steal a 2FA code in 30 seconds. Recovering an entire Gmail inbox took researchers 10-25 hours.
Is There a Fix?
Google released a patch in September 2025 after researchers disclosed the vulnerability in February. However, the researchers found a workaround that defeats Google’s fix.
That workaround remains under embargo while Google develops another patch scheduled for December 2025. No GPU vendors have committed to fixing the underlying hardware vulnerability that makes Pixnapping possible.
The researchers haven’t confirmed whether other Android manufacturers are affected, but they warn that the attack mechanisms exist on most Android devices.
Final Thoughts
This vulnerability shows how creative attackers can be when exploiting features that seem harmless. The fact that no permissions are required makes Pixnapping especially dangerous, as users have no way to know they’re being targeted.
Your best protection is installing Android security patches as soon as they become available. App developers currently have no known mitigation strategies to protect their users from this attack.
For more details on this story, refer to the Pixnapping Attack Research and the report from Cybernews.
We want to know your thoughts. What do you think about this story? Let us know in the comment section below!
Be sure to stay up-to-date with the latest streaming news, reviews, tips, and more by following the TROYPOINT Advisor with updates weekly.
This page includes affiliate links where TROYPOINT may receive a commission at no extra cost to you. Many times, visitors will receive a discount due to the special arrangements made for our fans. Learn more on my Affiliate Disclaimer page.
Exclusive Surfshark Discount
Your online activity is currently monitored by your ISP, app/addon/IPTV developers, government agencies, and the websites you visit.
- Become 100% anonymous while streaming and downloading.
- Use on Unlimited Devices & share 1 account with the entire family.
- Save 85% with the 24-Month Plan + Get 3 FREE Months.




