Google has released a November feature update for Pixel phones, introducing several new capabilities focused on user security and convenience. Notably, the update adds scam detection for messages, which alerts users to potentially fraudulent communications, and notification summaries to help users manage important messages. These features are rolling out to Pixel 6 and newer devices, aiming to enhance protection against social engineering attacks and improve overall user experience.
Separately, security researchers have disclosed a critical Android vulnerability known as Pixnapping (CVE-2025-48561), which allows malicious apps to capture screenshots of sensitive information without requiring special permissions. This flaw potentially exposes passwords, one-time codes, and financial data to attackers, affecting all modern Android devices, including those running the latest versions. While Pixnapping is not yet exploited in the wild, it underscores the ongoing risks to mobile device security and the need for prompt patching by Google.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
2 events from the most recent confirmed update back to the earliest known activity.
Kaspersky publicly disclosed the 'Pixnapping' vulnerability, tracked as CVE-2025-48561, describing it as an unblockable screenshotting issue affecting Android phones. The disclosure brought technical attention to a flaw that could allow screenshots despite expected protections.
Google rolled out a Pixel software update in November 2025 that included multiple feature upgrades and security improvements for Pixel devices. The update is the common event referenced across the coverage and likely addressed the Android screenshotting issue discussed in later reporting.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
4 references tracked. Mallory keeps watching after this page renders.
zdnet.com
Open sourcezdnet.com
Open sourcezdnet.com
Open sourcekaspersky.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.