Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Pixnapping is a research-demonstrated Android attack that can infer information displayed by other apps—including messages and authenticator codes—by measuring graphics-rendering timing, rather than taking a screenshot with ordinary permission. Researchers tested it on selected Google Pixel phones and a Samsung Galaxy S25, but those demonstrations do not show that every Android phone is vulnerable or that attackers are exploiting it in the wild. Install the latest security update offered for your exact phone; the available official update information does not establish that a particular patch level fully closes every reported Pixnapping variant.

What is Pixnapping?

Pixnapping is a proof-of-concept Android side-channel attack described by researchers in their 2025 paper, “Pixnapping: Bringing Pixel Stealing out of the Stone Age”. A malicious app can prompt a target app or website to render selected content, then infer pixel colors from timing differences in graphics operations.

That is different from malware simply reading another app’s private files or requesting standard screenshot permission. The attack instead uses Android rendering behavior as an indirect signal. The researchers describe a framework using Android intents and stacked, semi-transparent activities to involve victim pixels in rendering operations. On tested Pixel devices, the paper attributes the relevant timing behavior to GPU graphical data compression.

The researchers demonstrated the technique against browser content and non-browser apps, including Google Accounts, Gmail, Google Maps, Google Messages, Venmo, Signal, and Google Authenticator. These are demonstrated targets, not evidence that every version of those apps—or every Android app—can be attacked.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
Yubico - YubiKey 5C NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified - Protect Your Online Accounts
  • POWERFUL SECURITY KEY: The YubiKey 5C NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5C NFC secures 100+ of your favorite accounts, including email, password managers, and more
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5C NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
  • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts

Can Pixnapping steal 2FA codes or private messages?

It can infer information displayed on screen in the researchers’ demonstrations. The team reports recovering Google Authenticator codes in under 30 seconds on tested Pixel phones. That result applies to the specific proof-of-concept experiment and devices, not to every authenticator, every form of two-factor authentication, or every Android phone.

The paper reports a different result on the tested Samsung Galaxy S25: its implementation did not recover codes within 30 seconds because of significant noise. The researchers also demonstrated attacks against messaging apps, but that does not establish that accounts were compromised or that Pixnapping has been used against people in the wild. The study is evidence of a possible information-leakage technique, not a report of observed victim counts or real-world attacks.

Rank #2
Yubico - Security Key C NFC - Basic Compatibility - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.

Which Android phones were tested?

The researchers’ artifacts list five phone models and Android versions 13 through 16 in their test matrix. This is a bounded list of tested configurations, not a complete inventory of affected devices or a measure of how many Android phones are at risk.

Research evidence What it establishes
Pixel 6, Pixel 7, Pixel 8, and Pixel 9 Listed by the researchers among tested devices; the paper reports Google Authenticator code recovery in under 30 seconds on tested Pixel phones.
Samsung Galaxy S25 Listed among tested devices; the researchers say their implementation did not recover codes within 30 seconds because of significant noise.
Android 13, 14, 15, and 16 Versions listed in the researchers’ artifact test matrix. This does not mean every device running these versions has the same exposure.
Other Android devices Not established by the listed test matrix. “Not listed” does not mean safe, and the researchers’ broader concern is not a confirmed count of vulnerable models.

The paper says the attack framework was instantiated across phones with different hardware and graphics software, and the researchers suggest the underlying mechanisms could apply more broadly. That makes additional device testing relevant, but it is not proof that every Google or Samsung phone—or all Android phones—is affected. Carnegie Mellon’s October 13, 2025 report quotes researcher Riccardo Paccagnella, an assistant professor in the Software and Societal Systems Department: “Conceptually, it is as if any app could take a screenshot of other apps or websites without permission, which is a fundamental violation of Android’s security model.” That is his description of the security significance, not a claim that the tested exploit works on all devices.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #3
Yubico - YubiKey 5 NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-A or NFC, FIDO Certified - Protect Your Online Accounts
  • POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
  • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts

What is the Pixnapping patch status?

The research paper reports that the team disclosed the issue to Google on February 24, 2025; Google rated it high severity and assigned CVE-2025-48561. According to the paper, Google released a patch on September 2, 2025. The researchers then found a workaround that they said did not mitigate one attack instantiation and sent further findings to Google on September 8. They also reported to Samsung on September 19 that Google’s patch was insufficient to protect Samsung devices. These dates describe the events reported by the researchers; they do not, by themselves, establish the present fix status of any particular phone.

Google’s December 2025 Android Security Bulletin, published December 1, 2025 and updated March 6, 2026, says security patch level 2025-12-05 or later addresses issues listed in that bulletin. The bulletin information available here does not explicitly confirm that this patch level fully remediates the researchers’ reported workaround. Samsung says security update timing varies by device model and service version in its Mobile Security update index.

Rank #4
Yubico - YubiKey 5Ci - Multi-Factor authentication (MFA) Security Key and passkey for iPhone/Android/PC, Dual connectors for Lighting/USB-C, FIDO Certified
  • POWERFUL SECURITY KEY: The YubiKey 5 is a versatile physical passkey that protects your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 secures 100+ of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 via USB and tap it to authenticate. No batteries, no internet connection, and no extra fees required.
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

How to protect your Android phone

  1. Install the newest update offered for your exact device. Open your phone’s Settings and use its system software update option; menu wording and location can differ by manufacturer and Android version. Install available security updates and restart if prompted.
  2. Check the displayed security patch level. In Settings, look in the phone information or Android version details for “Android security update” or a similarly named field. Record the date shown, but do not treat a date alone as proof that every Pixnapping variant is fixed.
  3. Consult the manufacturer’s model-specific update information. Check Google or Samsung support and the relevant security update page for your exact model and rollout. Samsung notes that timing varies by device and service version.
  4. Keep sensitive apps and Android up to date. Install available updates for your browser, messaging apps, and authenticator as well as system updates. The cited research does not establish an app-only workaround that replaces an Android security fix.

The most useful evidence-backed step is software updating, but the available official bulletin and manufacturer information do not map a specific current patch level to complete remediation of the reported workaround across all tested phones. If your device has no update available, check the manufacturer’s support information for that model rather than assuming it is either protected or vulnerable.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.