CVE-2025-48561 is an Android side-channel information disclosure vulnerability, referred to as Pixnapping, that allows a malicious local application to infer and reconstruct sensitive content displayed on the device screen. The issue arises from side-channel leakage in the Android graphics and display pipeline on modern devices, and reported attack chains combine Android app invocation behavior, graphical blur operations, rendering behavior, timing observations, and the GPU.zip side channel to recover pixels from content rendered by other applications. Researchers demonstrated reconstruction of visible screen data from applications such as authenticators, messaging clients, email, mapping, and financial applications. The vulnerability affects modern Android devices, with testing reported on Android 13 through 16 and particularly on several Google Pixel models, while reliability varied across hardware platforms.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
No valid public exploits. Mallory filtered out 2 candidates as fakes, detection scripts, or README-only repos.
All candidate exploits were filtered out by Mallory's validation.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
28 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A high-severity Android vulnerability that enables a malicious app with no special permissions to reconstruct screen contents pixel by pixel using Android APIs, blur effects, VSync timing, and the GPU.zip side channel, exposing sensitive data such as seed phrases and 2FA codes.
A side-channel vulnerability in modern Android devices that enables the Pixnapping pixel-stealing attack, allowing a malicious app to infer and reconstruct information displayed on the screen of other apps.
An Android side-channel attack technique dubbed Pixnapping that abuses Android APIs, pixel rendering, blur operations, and the GPU.Zip side channel to steal sensitive on-screen data such as 2FA codes, messages, emails, and app content without requiring abusive permissions.
An Android side-channel attack technique dubbed Pixnapping that abuses Android APIs, pixel rendering, blur operations, and the GPU.Zip side channel to steal sensitive on-screen data such as 2FA codes, messages, emails, and app content without requiring abusive permissions.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.