CVE-2025-48561, dubbed "Pixnapping," is an Android local information disclosure vulnerability caused by side-channel leakage from on-screen rendering. According to the provided content, a malicious Android application can reconstruct sensitive screen content pixel by pixel without requiring special permissions or additional execution privileges. The attack reportedly combines Android Intents to invoke target activities, the Android window blur API to induce graphical operations over sensitive rendered content, VSync timing/rendering behavior, and the GPU.zip side channel to infer displayed pixels. The issue affects Android devices tested on versions 13 through 16 and targets data rendered through the Android graphics pipeline, including content from apps such as Google Authenticator, Signal, Gmail, Google Accounts, Venmo, and Google Maps. The vulnerable condition is described as leakage through Android's rendering/compositing path, including SurfaceFlinger-related behavior, rather than a conventional memory corruption flaw.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
No valid public exploits. Mallory filtered out 2 candidates as fakes, detection scripts, or README-only repos.
All candidate exploits were filtered out by Mallory's validation.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
27 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A high-severity Android vulnerability that enables a malicious app with no special permissions to reconstruct screen contents pixel by pixel using Android APIs, blur effects, VSync timing, and the GPU.zip side channel, exposing sensitive data such as seed phrases and 2FA codes.
An Android side-channel attack technique dubbed Pixnapping that abuses Android APIs, pixel rendering, blur operations, and the GPU.Zip side channel to steal sensitive on-screen data such as 2FA codes, messages, emails, and app content without requiring abusive permissions.
An Android side-channel attack technique dubbed Pixnapping that abuses Android APIs, pixel rendering, blur operations, and the GPU.Zip side channel to steal sensitive on-screen data such as 2FA codes, messages, emails, and app content without requiring abusive permissions.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.