Learn languages naturally with fresh, real content!

tap to translate recording

Explore By Region

flag A new Android flaw lets malicious apps steal 2FA codes and messages via GPU timing attacks, affecting most devices despite a partial fix.

flag A newly discovered Android vulnerability called "Pixnapping," tracked as CVE-2025-48561, allows malicious apps to steal sensitive on-screen data like two-factor authentication codes and private messages using a side-channel attack that exploits GPU timing. flag Researchers from UC Berkeley, UC San Diego, the University of Washington, and Carnegie Mellon demonstrated the flaw affects nearly all modern Android devices, including Pixel and Samsung flagship models, and can extract 2FA codes in under 30 seconds. flag The attack tricks legitimate apps into displaying content, then reconstructs it via pixel-level timing analysis without user consent. flag Google has released a partial fix in the September update, but researchers confirm the exploit can bypass it, with a full patch expected in December. flag No evidence of real-world use has been found as of October 14, 2025. flag Users are advised to keep devices updated and avoid untrusted apps.

15 Articles