Yes—Pixnapping is a demonstrated Android attack that can recover information displayed by another app, including one-time two-factor authentication (2FA) codes, without requesting Android permissions. The researchers showed it on specific Pixel and Samsung phones, not on every Android device. Google released an initial patch in September 2025, but the researchers later reported a workaround and said Samsung devices were not protected by that patch. The available project timeline does not establish the patch status of every vendor today, so keep your device updated and check its own security-update status.
What Pixnapping does—and what it does not do
Pixnapping is an on-screen disclosure attack. A malicious app can infer pixels that another app or website has rendered, then reconstruct visible content. It does not simply receive a normal screenshot, and it does not demonstrate access to everything stored by the other app.
The practical boundary is whether sensitive information is displayed. A message, email, authentication code, financial detail, or map timeline shown on screen may be exposed during the attack. Data kept internally and never rendered is outside the demonstrated technique; Pixnapping does not by itself mean an attacker obtains an app’s private database or cryptographic keys that never appear on the display.
How the attack recovers visible information
- Make the target display the sensitive screen. The malicious app invokes a target activity so that the other app renders the information.
- Apply graphical operations to selected pixels. The attack uses Android window-blur and overlay behavior to affect chosen parts of the rendered image.
- Measure rendering side effects and reconstruct the image. The app uses the GPU.zip hardware side channel to measure those effects pixel by pixel, repeats the process, then applies optical character recognition (OCR) to interpret the recovered image.
This is why the attack is serious even though it does not ask for conventional permissions: it abuses graphics behavior and a hardware side channel rather than relying on permission to read the target app’s data.
The Tool Desk
Outbyte PC Repair FREEClear out junk files and repair common Windows errorsFree Scan →Outbyte Driver Updater FREEScan for outdated or missing drivers - takes under a minuteDriver Scan →#1 Best Overall
- Compatible Model: Specifically Designed for Samsung Galaxy A12, A13, A32, A03s, A02s, A42. Please double check your device model before purchasing
- Privacy Protection: Screen is only visible to persons directly in front of screen, Keep your information safe and prevent others from viewing the information by looking over
- Superior Quality: 0.33mm ultra-thin tempered glass, Highly durable, and scratch resistant, surface hardness 9H and topped with oleophobic coating to reduce fingerprints
- Case Friendly: Compatible with most mobile phone cases on the market, Extra space is left around the borders for your case to wrap around the edges of your phone
- HPTech is committed to provide 100% customer satisfaction, Please email us by Via Amazon message System for any questions
Can Pixnapping steal a 2FA code?
Yes. The researchers demonstrated recovery of ephemeral codes from Google Authenticator in under 30 seconds, while hiding the attack from the user and requiring no Android permissions. A one-time code is useful only briefly, but a malicious app that reads it while it is displayed could capture it during that window.
The proof of concept also recovered data from Google Accounts, Gmail, Perplexity AI, Signal, Venmo, Google Messages, and Google Maps. These demonstrations concern information made visible on screen; they do not establish that Pixnapping can extract every kind of secret from those services.
Rank #2
- 【Compatible with Samsung Galaxy S23+/S23 Plus】Include 2 Pack Tempered Glass Privacy Screen Protector for Galaxy S23+/S23 Plus 【Support Finger Print Unlock】. Please check your phone model before purchase.
- 【Privacy Protection】 Privacy glass screen is only visible to person who is directly in front of Screen. Protect your personal privacy effectively.
- 【Case Friendly】Compatible with most mobile phone cases.
- 【Easy Installation】 A handy installation tray is provided for your easy quick installation, not easy to fall off, no bubbles.
- 【Superior Quality】9H hardness privacy screen protector resists accidental drops and impacts. Light transmittance of 99.9%, maintain original touch experience and HD screen.
Which phones were demonstrated as vulnerable?
| Device | Research demonstration | What that establishes |
|---|---|---|
| Google Pixel 6, Pixel 7, Pixel 8, and Pixel 9 | Tested by the Pixnapping researchers on Android 13 through Android 16 | The attack was demonstrated on these Pixel models in the tested Android-version range. |
| Samsung Galaxy S25 | Tested by the Pixnapping researchers on Android 13 through Android 16 | The attack was demonstrated on this Samsung model; the researchers separately reported that the initial Google patch did not protect Samsung devices. |
| Other Android devices | Not confirmed by the researchers in the cited project findings | The researchers said the core mechanisms are typically available on devices from other vendors, but did not confirm those vendors. Treat broader exposure as possible, not as a demonstrated fact about every model. |
Android version alone is not a complete way to judge exposure. Vendor implementation and installed security patches matter too. The demonstrated devices are evidence of a real risk, not a complete list of affected or safe phones.
Has Google patched Pixnapping?
Google released an initial patch on September 2, 2025, after rating the issue “High severity” and assigning it CVE-2025-48561. The researchers disclosed the findings to Google on February 24, 2025. They later found a workaround, reported new findings to Google on September 8, 2025, and told Samsung on September 19, 2025, that the Google patch did not protect Samsung devices.
Do these 3 things before closing this tab:
1Clear out junk files and repair common Windows errors2Scan for outdated or missing drivers - takes under a minute3Repair Windows errors before they cause bigger problemsRank #3
- 【Compatible with Samsung Galaxy S25+/S25 Plus】Include 2 Pack Tempered Glass Privacy Screen Protector for Galaxy S25+/S25 Plus【Support Finger Print Unlock】. Please check your phone model before purchase.
- 【Privacy Protection】 Privacy glass screen is only visible to person who is directly in front of Screen. Protect your personal privacy effectively.
- 【Case Friendly】Compatible with most mobile phone cases.
- 【Easy Installation】 A handy installation tray is provided for your easy quick installation, not easy to fall off, no bubbles.
- 【Superior Quality】9H hardness privacy screen protector resists accidental drops and impacts. Light transmittance of 99.9%, maintain original touch experience and HD screen.
The project timeline said Google planned an additional Pixnapping patch in the December Android security bulletin. It also reported that, as of October 2025, no GPU vendor had committed to patching GPU.zip. Those dated statements do not confirm whether every planned fix was later delivered, or whether a particular phone is protected now. Check the security patch level shown in your phone’s Settings and your manufacturer’s current security bulletins; do not assume that installing one Android update protects every vendor’s device.
What Android users should do
- Install security updates promptly. The researchers’ direct advice is to install Android patches as soon as they become available. Also install updates from your phone manufacturer, since fixes can vary by vendor and device.
- Be cautious with apps you do not trust. Avoid installing apps from untrusted sources, especially apps with no clear reason to be on your phone. Pixnapping’s demonstrated attack did not require Android permissions, so permission prompts alone are not a reliable way to rule it out.
- If you suspect a malicious app was active, treat displayed secrets as potentially seen. Do not rely on a code that was visible during the suspected exposure; use a fresh code. Review account security and recovery options for accounts whose sensitive screens may have been displayed.
- Use your device’s patch status, not a blanket claim about Android. Check Settings for the installed Android security update and consult the phone maker’s bulletin or support information for your exact model.
Is Pixnapping being used in real-world attacks?
The researchers said they did not know whether Pixnapping had been exploited in the wild. Their proof of concept shows that the attack is technically possible under the demonstrated conditions; it is not evidence that criminals have deployed it against ordinary users.
Quick Recap
Rank #4
- [Fingerprint Unlocked] Designed for Samsung Galaxy S24 5G 6.2-inch. For a better unlocking experience, please go to Settings of your device to activate the Touch Sensitivity and re-enter your fingerprint after applying the film
- [Privacy Protection] Screen is only visible to person directly in front of screen. Protects your personal privacy effectively and ensures comfortable viewing experience
- [Premium Material] Built with 9H high hardness tempered glass. Highly protect the screen from unwanted scratches and abrasions
- [Anti-Fingerprint] The hydrophobic and oleophobic coating effectively prevents the residue of fingerprints, oil and watermark from gathering on the screen
- [Case-Friendly] There is enough edge space around the borders for your case to wrap around the edges of your mobile. Compatible with most phone cases
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

