Ausnahme gefangen: SSL certificate problem: certificate is not yet valid 📌 Severe Privacy Vulnerability ‘Acropalypse’ Affects Windows 11 Snipping Tool

🏠 Team IT Security News

TSecurity.de ist eine Online-Plattform, die sich auf die Bereitstellung von Informationen,alle 15 Minuten neuste Nachrichten, Bildungsressourcen und Dienstleistungen rund um das Thema IT-Sicherheit spezialisiert hat.
Ob es sich um aktuelle Nachrichten, Fachartikel, Blogbeiträge, Webinare, Tutorials, oder Tipps & Tricks handelt, TSecurity.de bietet seinen Nutzern einen umfassenden Überblick über die wichtigsten Aspekte der IT-Sicherheit in einer sich ständig verändernden digitalen Welt.

16.12.2023 - TIP: Wer den Cookie Consent Banner akzeptiert, kann z.B. von Englisch nach Deutsch übersetzen, erst Englisch auswählen dann wieder Deutsch!

Google Android Playstore Download Button für Team IT Security



📚 Severe Privacy Vulnerability ‘Acropalypse’ Affects Windows 11 Snipping Tool


💡 Newskategorie: Hacking
🔗 Quelle: blackhatethicalhacking.com

Severe Privacy Vulnerability ‘Acropalypse’ Affects Windows 11 Snipping Tool

Premium Content

Patreon
Subscribe to Patreon to watch this episode.
Reading Time: 3 Minutes

Acropalypse Flaw

Microsoft’s Windows 11 Snipping Tool has been found to contain a severe privacy flaw named ‘acropalypse’. The flaw, which has already been discovered in Google Pixel’s Markup Tool, allows partially edited content to be recovered. Security researchers David Buchanan and Simon Aarons recently found that the original image data is retained even after editing or cropping out. The bug poses a significant privacy risk, as it can allow sensitive information, such as credit card numbers or revealing photos, to be partially recovered.

The researchers created an online screenshot recovery tool, acropalypse, which attempts to recover edited images created on Google Pixel.

See Also: So you want to be a hacker?
Offensive Security, Bug Bounty Courses

Acropalypse privacy flaw also affects the Windows 11 Snipping Tool.

Today, software engineer Chris Blume confirmed that the acropalypse privacy flaw also affects the Windows 11 Snipping Tool. Overwriting an existing file in the tool leaves unused data behind, making it partially recoverable.

To test this flaw, BleepingComputer opened an existing PNG file in the Windows 11 Snipping Tool, cropped it, and then saved the changes to the original file. Surprisingly, the file sizes for the original image file and the cropped image file were the same, indicating that unused data was not truncated, but left behind.

While the untruncated data may not be visible in an image viewer, it can be used to recreate sensitive portions of the original image. Buchanan shared a Python script with BleepingComputer that can be used to recover Windows files.

Recovery of sensitive information

Even though the online acropalypse screenshot recovery app does not currently work with Windows files, Buchanan warned that a potential privacy risk exists. Users may have sensitive information in screenshots that they cropped out, but this information can still be partially recovered by someone with the right tools.

Microsoft acknowledged the reports and stated that they are investigating the issue to protect their customers. However, the researchers noted that not all PNG files, such as optimized PNGs, are affected by this flaw. Additionally, opening an untruncated PNG file in an image editor and saving it to another file can strip off the unused data at the end, making it no longer recoverable.

The Windows 11 Snipping Tool also behaves similarly with JPG files, leaving untruncated data if overwritten. Buchanan warned that his exploit does not currently work on JPGs, but it could be possible.

Are u a security researcher? Or a company that writes articles or write ups about Cyber Security, Offensive Security (related to information security in general) that match with our specific audience and is worth sharing?

If you want to express your idea in an article contact us here for a quote: info@blackhatethicalhacking.com

Source: bleepingcomputer.com

Source Link

Merch

Offensive Security & Ethical Hacking Course

Begin the learning curve of hacking now!


Information Security Solutions

Find out how Pentesting Services can help you.

The post Severe Privacy Vulnerability ‘Acropalypse’ Affects Windows 11 Snipping Tool first appeared on Black Hat Ethical Hacking. ...



📌 Severe Privacy Vulnerability ‘Acropalypse’ Affects Windows 11 Snipping Tool


📈 86.7 Punkte

📌 Microsoft fixes Acropalypse privacy bug in Windows 11 Snipping Tool


📈 55.52 Punkte

📌 Windows Snipping-Tool anfällig für "Acropalypse"


📈 49.22 Punkte

📌 Windows Snipping-Tool anfällig für "Acropalypse"


📈 49.22 Punkte

📌 Microsoft korrigiert "Acropalypse"-Fehler im Windows Snipping-Tool


📈 49.22 Punkte

📌 Microsoft korrigiert "Acropalypse"-Fehler im Windows Snipping-Tool


📈 49.22 Punkte

📌 Windows 11 Snipping Tool 'aCropalypse' bug fixed with emergency update from Microsoft


📈 49.22 Punkte

📌 Windows Snipping-Tool: “Acropalypse”-Fehler wurde behoben


📈 49.22 Punkte

📌 Microsoft Issues Patch for aCropalypse Privacy Flaw in Windows Screenshot Tools


📈 33.04 Punkte

📌 Acropalypse: Auch Windows' Screenshot-Tool kann Sicherheitsproblem sein


📈 32.12 Punkte

📌 aCropalypse now! Cropped and redacted images suffer privacy fail on Google Pixel smartphones


📈 31.17 Punkte

📌 Windows 11 Snipping Tool privacy bug exposes cropped image content


📈 30.64 Punkte

📌 Windows 11 Snipping Tool Privacy Bug: Inspecting PNG Files, (Wed, Mar 22nd)


📈 30.64 Punkte

📌 Windows 11 Snipping Tool hit by major privacy flaw


📈 30.64 Punkte

📌 Acropalypse flaw in Google Pixel’s Markup tool allowed the recovery of edited images


📈 30.25 Punkte

📌 Microsoft releases update for Win10 Snip & Sketch, Win11 Snipping Tool to resolve privacy flaw


📈 28.77 Punkte

📌 Microsoft issues fix for the Snipping Tool’s privacy flaw


📈 28.77 Punkte

📌 Severe MDHexRay bug affects 100+ GE Healthcare imaging systems


📈 27.95 Punkte

📌 Severe Vulnerabilities in Realtek SDK Affects Around Millions of IoT Devices


📈 27.95 Punkte

📌 Microsoft Released an Update for Windows Snipping Tool Vulnerability, (Sat, Mar 25th)


📈 27.58 Punkte

📌 Windows 11 also vulnerable to “aCropalypse” image data leakage


📈 26.74 Punkte

📌 Acropalypse: Microsoft fixt Fehler bei Screenshot-Tools von Windows


📈 26.74 Punkte

📌 Update verfügbar: Microsoft patcht Acropalypse-Bug in Windows 10/11


📈 26.74 Punkte

📌 How to open the Snipping Tool to take a screenshot instantly on Windows 10 or Windows 11


📈 26.21 Punkte

📌 Windows 10 und Windows 11: So nutzt ihr das Snipping Tool richtig


📈 26.21 Punkte

📌 Filter PNGs for Acropalypse using Compute@Edge


📈 24.88 Punkte

📌 Google: Ursache für Acropalypse-Lücke in Android seit Jahren bekannt


📈 24.88 Punkte

📌 Acropalypse: Zensierte Bilder rekonstruierbar


📈 24.88 Punkte

📌 Windows 10 RS5: Neues Snipping-Tool und mehr Neues


📈 24.34 Punkte

📌 Microsoft Won’t Kill the Classic Snipping Tool on Windows 10 With Next Update


📈 24.34 Punkte

📌 Windows 10 Snipping-Tool: Neuer Name und Funktionen


📈 24.34 Punkte

📌 Microsoft to Kill Off Windows Snipping Tool in Future Update


📈 24.34 Punkte

📌 Aero Shake und das Snipping Tool verschwinden aus Windows 10


📈 24.34 Punkte

📌 Windows 10: Paint and Snipping Tool now update from the Microsoft Store


📈 24.34 Punkte

📌 How to Fix Snipping Tool Issues on Windows 11


📈 24.34 Punkte











matomo