The Windows 11 cropping tool shares a Google Pixel security flaw

A glitched screenshot taken with Windows 11, run through the Acropalypse exploit script.
(Image credit: Twitter / David Buchanan)

Fresh off the back of Google Pixel’s Markup tool being found to have retained image data even when edited out, software engineer Chris Blume has found a similar bug in the Windows 11 Snipping Tool.

Dubbed “acropalypse”, the phenomenon works when an existing file is overwritten with edits, such as crops. Rather than omitting the cropped data, the image file retains it, potentially allowing it to be recovered and used in an identity theft attack.

Per BleepingComputer, the researchers who discovered the original Google Pixel flaw, David Buchanan and Simon Aarons, have launched a tool demonstrating that this is possible, although we should probably stress that you should only use it for testing purposes.

Acropalypse on Windows 11

The Windows rendition of the bug, which also applies to Windows 10’s Snip and Sketch tool, has been corroborated by vulnerability expert Will Dormann and BleepingComputer in testing, but it’s also easily verifiable by anyone.

In Snipping Tool, once you’ve take a screenshot, cropped it, and saved it as a copy of the original, compare the file sizes. With any (bad) luck, they’re the same.

And, as you can notice by opening one in a text editor, PNG files generally require that all files end with an “IEND” data chunk, but Snipping Tool fails to both remove the data, and presents it after the chunk.

That Google Pixel and Windows are both susceptible to a highly similar bug with the potential to do quite a bit of harm should be concerning given that, as Buchanan noted in a profane tweet on Tuesday, the Markup and Snipping tools are two “entirely unrelated” codebases.

TOPICS
Luke Hughes
Staff Writer

 Luke Hughes holds the role of Staff Writer at TechRadar Pro, producing news, features and deals content across topics ranging from computing to cloud services, cybersecurity, data privacy and business software.

Read more
A laptop on a desk with the Windows 11 background on its screen.
Microsoft is adding image editing and compression to its Windows Share feature - and I couldn't be happier
A woman sitting in a chair looking at a Windows 11 laptop
Windows 11’s screenshot tool is getting a nifty new time-saving ability
Google Chrome
Google Chrome's Incognito mode is now more private in Windows 11 - and it's all thanks to Microsoft
OneDrive on a Laptop
Microsoft One Drive for Business might not be storing your data as securely as you might hope
hacker.jpeg
Thousands of GitHub repositories exposed via Microsoft Copilot
Location Data
Cloudflare CDN flaw could expose user location simply by sending an image
Latest in Security
Data Breach
Thousands of healthcare records exposed online, including private patient information
China
Juniper patches security flaws which could have let hackers take over your router
Representational image depecting cybersecurity protection
GitLab has patched a host of worrying security issues
Ai tech, businessman show virtual graphic Global Internet connect Chatgpt Chat with AI, Artificial Intelligence.
AI agents can be hijacked to write and send phishing attacks
China
Volt Typhoon threat group had access to American utility networks for the best part of a year
Abstract image of cyber security in action.
MassJacker malware targets those looking for pirated software
Latest in News
Quordle on a smartphone held in a hand
Quordle hints and answers for Sunday, March 16 (game #1147)
NYT Strands homescreen on a mobile phone screen, on a light blue background
NYT Strands hints and answers for Sunday, March 16 (game #378)
NYT Connections homescreen on a phone, on a purple background
NYT Connections hints and answers for Sunday, March 16 (game #644)
Three iPhone 16 handsets on show
Apple could launch an iPhone 17 Ultra this year – but we've heard these rumors before
Super Mario Odyssey
ChatGPT is the ultimate gaming tool - here's 4 ways you can use AI to help with your next playthrough
Ray-Ban smart glasses with the Cpperni logo, an LED array, and a MacBook Air with M4 next to ecah other.
ICYMI: the week's 7 biggest tech stories from Twitter's massive outage to iRobot's impressive new Roombas