PT-2025-36080 · Google · Android
Published
2025-09-01
·
Updated
2025-10-15
·
CVE-2025-48561
CVSS v3.1
5.5
5.5
Medium
Base vector | Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Android versions 13 through 16
Description
A side-channel information disclosure issue exists in the Android operating system. This flaw allows a malicious application to potentially access data displayed on the screen, including sensitive information like two-factor authentication (2FA) codes, Google Maps timelines, and data from applications such as Google Authenticator, Gmail, Signal, Venmo, and others. The attack, named Pixnapping, exploits Android APIs and a hardware side channel involving the GPU to reconstruct pixels and extract displayed data without requiring special permissions. The vulnerability leverages the GPU's compression function and window blurring API to steal data. The issue is partially addressed by Google with CVE-2025-48561, but a complete fix is considered infeasible. The attack can determine if a specific application is installed on the device, bypassing restrictions introduced in Android 11. The vulnerability does not require user interaction for exploitation.
Recommendations
Avoid installing applications from untrusted sources.
Use hardware-based 2FA methods, such as YubiKey.
Consider using hardware wallets for cryptocurrency.
Fix
Side Channel Attack
Found an issue in the description? Have something to add? Feel free to write us 👾
dbugs@ptsecurity.com
Weakness Enumeration
Related Identifiers
BDU:2025-11675
CVE-2025-48561
Affected Products
Android
References · 14
- https://android.googlesource.com/platform/frameworks/native/+/20465375a1d0cb71cdb891235a9f8a3fba31dbf6 · Patch
- https://bdu.fstec.ru/vul/2025-11675 · Security Note
- https://source.android.com/security/bulletin/2025-09-01 · Vendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2025-48561 · Security Note
- https://twitter.com/catnap707/status/1978255138671284555 · Twitter Post
- https://t.me/cveNotify/136581 · Telegram Post
- https://t.me/true_secator/7522 · Telegram Post
- https://t.me/opennews/14242 · Telegram Post
- https://twitter.com/androidmalware2/status/1977989328690163850 · Twitter Post
- https://twitter.com/The_Hunt_x/status/1978030088320102426 · Twitter Post
- https://twitter.com/grok/status/1978178845711925260 · Twitter Post
- https://twitter.com/CVEnew/status/1963677384776769741 · Twitter Post
- https://t.me/CVEtracker/31725 · Telegram Post
- https://twitter.com/MeridianEU/status/1978109336736928095 · Twitter Post