aCropalypse Flaw Allows Recovery of Sensitive Data Removed From Pixel Screenshots, Researchers Say

Google has reportedly patched the aCropalypse flaw on Pixel 4a, Pixel 5a, Pixel 7, and Pixel 7 Pro smartphones.

Advertisement
Written by David Delima, Edited by Siddharth Suvarna | Updated: 20 March 2023 12:59 IST
Highlights
  • The aCropalypse vulnerability affects the markup tool on Pixel phones
  • A tool to demonstrate aCropalypse allows users to recover removed details
  • Owners of select Pixel phone can install an update that blocks the flaw

The aCropalypse flaw has existed for the past five years, according to researchers

Photo Credit: Google

Pixel smartphones were previously affected by a security flaw that could allow any user to restore sensitive details cropped or redacted from screenshots, according to data shared by security researchers. A security flaw in Google's markup tool for Pixel smartphones allowed edited screenshot images to retain some of the original information, letting users recover details that were previously obfuscated by the sender. The vulnerability, which has existed for several years, has now been patched by Google on currently supported Pixel handsets.

Security researchers Simon Aarons and David Buchanan discovered a security flaw dubbed aCropalypse, that affects the markup tool used to crop, edit, and highlight screenshots on Pixel handsets. According to details shared by Buchanan, Android 10 introduced some changes to the system that caused data that had been edited out from screenshot to remain in the image. As a result, that data can be recovered by any user who received the image, including strangers on the Internet.

In a thread on Twitter, Aarons explained how the aCropalypse vulnerability works using an image he sent to Discord user Retr0id using the popular communication app. An image of a credit card that has been cropped and redacted with the "black pen" tool is shown to be downloaded, then subjected to a recovery process that results in an uncropped image of a fake bank website with the same credit card, along with its number visible.

Advertisement

According to Aarons, if the edited screenshot in PNG format has a smaller file size, as is the case with many cropped images, then “the trailing portion of the original file is left behind, after the new file is supposed to have ended”. This trailing portion of the file can then be recovered, he adds. The researcher has also published a tool that demonstrates how the aCropalypse vulnerability functions, allowing users to upload a screenshot to try and recover the original file.

Advertisement

Meanwhile, a 9to5Google report citing an early access version of an FAQ page for the vulnerability, states that not all images shared online are affected by the image. Some platforms, such as Twitter, process all uploaded images in such a way that it is not affected by the aCropalypse security flaw. However, on platforms like Discord that share images as-is, users who have shared screenshots using their Pixel smartphones since Android 10 could be affected by the vulnerability.

Owners of the Pixel 4a, Pixel 5a, Pixel 7, and Pixel 7 Pro, can update to the latest March security release to install a security fix for the flaw (CVE-2023-21036) which has a "high" severity classification, as per the report. However, there's no word from Google on when other supported Pixel phones will receive the fixes, or whether the company will update Pixel handsets that are no longer receiving software updates with a fix for the flaw. 

Advertisement


After facing headwinds in India last year, Xiaomi is all set to take on the competition in 2023. What are the company's plans for its wide product portfolio and its Make in India commitment in the country? We discuss this and more on Orbital, the Gadgets 360 podcast. Orbital is available on Spotify, Gaana, JioSaavn, Google Podcasts, Apple Podcasts, Amazon Music and wherever you get your podcasts.
Affiliate links may be automatically generated - see our ethics statement for details.
 
REVIEW
  • Design
  • Display
  • Software
  • Performance
  • Battery Life
  • Camera
  • Value for Money
  • Good
  • Reliable camera performance
  • Lean software with guaranteed updates
  • Stereo speakers
  • Vivid OLED display
  • Light, built well
  • Bad
  • Relatively low battery capacity
  • No ultra-wide camera
 
KEY SPECS
Display 5.81-inch
Processor Qualcomm Snapdragon 730G
Front Camera 8-megapixel
Rear Camera 12.2-megapixel
RAM 6GB
Storage 128GB
Battery Capacity 3140mAh
OS Android 10
Resolution 1080x2340 pixels
NEWS
REVIEW
  • Design
  • Display
  • Software
  • Performance
  • Battery Life
  • Camera
  • Value for Money
  • Good
  • Sharp, 90Hz display
  • Good quality cameras
  • Good gaming performance
  • Bloatware-free software, timely updates
  • Good battery life
  • IP68 rating
  • Bad
  • Video recording could be better
  • Gets warm under load
  • No bundled charger
  • Relatively slow charging
 
KEY SPECS
Display 6.30-inch
Processor Google Tensor G2
Front Camera 10.8-megapixel
Rear Camera 50-megapixel + 12-megapixel
RAM 8GB
Storage 128GB
OS Android 13
Resolution 1080x2400 pixels
NEWS
REVIEW
  • Design
  • Display
  • Software
  • Performance
  • Battery Life
  • Camera
  • Value for Money
  • Good
  • Sharp, 120Hz display
  • Good quality cameras
  • Good gaming performance
  • Bloatware-free software, timely updates
  • Premium design, IP68 rating
  • Bad
  • Gets warm under load
  • No bundled charger
  • Underwhelming battery life
  • Relatively slow charging
 
KEY SPECS
Display 6.70-inch
Processor Google Tensor G2
Front Camera 10.8-megapixel
Rear Camera 50-megapixel + 48-megapixel + 12-megapixel
RAM 12GB
Storage 128GB, 256GB
OS Android 13
Resolution 1440x3120 pixels
NEWS

Catch the latest from the Consumer Electronics Show on Gadgets 360, at our CES 2026 hub.

Advertisement
Popular Mobile Brands
  1. Here's How Much the Vivo V70 Series Could Cost in India
  2. Oppo Find N6 Bags Certification Ahead of Launch in the UAE
  3. iQOO 15 Ultra to Feature Shoulder Triggers, More Gaming Features
  4. Apple Sees Record Growth in iPhone Shipments in India
  5. Physicists Develop New Method to Detect Tiny Fluctuations in Spacetime
  6. Here's How WhatsApp's Secondary Accounts for Minors Might Work
  7. Oppo K15 Turbo, Poco X8 Pro Series Could Launch With These MediaTek Chips
  8. Samsung Responds After Galaxy S25+ Allegedly Explodes During Charging
  1. iQOO 15 Ultra Confirmed to Feature Touch-based Shoulder Triggers With Haptic Feedback
  2. iPhone Shipments in India Rise to 14 Million Units in 2025 as Apple Sees Record Year: Report
  3. Oppo Find N6 Listed on TDRA Website, Hinting at Imminent Launch in the UAE
  4. NASA’s JWST Uncovers a ‘Feeding Frenzy’ That Births Supermassive Black Holes
  5. NASA Confirms Historic Artifacts Will Fly on Artemis II Moon Mission
  6. Hubble Reveals How Blue Straggler Stars Stay Young in Ancient Clusters
  7. NASA Tests New Wing Design That Could Transform Airliner Efficiency
  8. James Webb Captures Stunning Infrared Image of the Helix Nebula Eye of God
  9. Mark Now Streaming Online: Where to Watch This Kannada Action Thriller Online?
  10. Physicists Develop New Method to Detect Tiny Fluctuations in Spacetime
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.