A new attack called Pixnapping allows malicious apps on Android devices to covertly steal sensitive data, including 2FA codes and location timelines, in under 30 seconds without needing system permissions. Although Google has released mitigations, researchers indicate that modified versions of the attack can bypass these updates, affecting devices like Google Pixel and Samsung Galaxy S25.
Want More Context? 🔎






