
Follow ZDNET: Add us as a preferred source on Google.
ZDNET’s key takeaways
- Pixnapping could be used to steal private data, including 2FA codes.
- Side-channel attack abuses Google Android APIs to steal data on display.
- Flaw is partially patched, although a more complete fix is due in December.
A new attack method demonstrated by researchers could lead to the theft of two-factor authentication (2FA) codes and more on Android devices.

![[CITYPNG.COM]White Google Play PlayStore Logo – 1500×1500](https://startupnews.fyi/wp-content/uploads/2025/08/CITYPNG.COMWhite-Google-Play-PlayStore-Logo-1500x1500-1-630x630.png)