TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

Acropalypse: a vulnerability in Google's screenshot editing tool

137 点作者 PenguinRevolver大约 2 年前

9 条评论

hewtronic大约 2 年前
For a hint at how the bug works, see this <a href="https:&#x2F;&#x2F;issuetracker.google.com&#x2F;issues&#x2F;180526528" rel="nofollow">https:&#x2F;&#x2F;issuetracker.google.com&#x2F;issues&#x2F;180526528</a> (more details coming soon™)<p>From <a href="https:&#x2F;&#x2F;twitter.com&#x2F;David3141593&#x2F;status&#x2F;1636979466860744704" rel="nofollow">https:&#x2F;&#x2F;twitter.com&#x2F;David3141593&#x2F;status&#x2F;1636979466860744704</a><p>Also: you [can] do a basic check with tools like exiftool - it will report &quot;Warning: [minor] Trailer data after PNG IEND chunk&quot; on vulnerable images.<p>From: <a href="https:&#x2F;&#x2F;twitter.com&#x2F;David3141593&#x2F;status&#x2F;1636981307891671041" rel="nofollow">https:&#x2F;&#x2F;twitter.com&#x2F;David3141593&#x2F;status&#x2F;1636981307891671041</a>
评论 #35208667 未加载
e4e5大约 2 年前
Nice write-up here: <a href="https:&#x2F;&#x2F;www.da.vidbuchanan.co.uk&#x2F;blog&#x2F;exploiting-acropalypse.html" rel="nofollow">https:&#x2F;&#x2F;www.da.vidbuchanan.co.uk&#x2F;blog&#x2F;exploiting-acropalypse...</a>
ZiiS大约 2 年前
The fact this wasnt triaged as a security bug is unforgivable <a href="https:&#x2F;&#x2F;issuetracker.google.com&#x2F;issues&#x2F;180526528" rel="nofollow">https:&#x2F;&#x2F;issuetracker.google.com&#x2F;issues&#x2F;180526528</a>
评论 #35209229 未加载
jsjohnst大约 2 年前
These types of issues are exactly why whenever it’s sensitive, I screenshot, crop&#x2F;edit, then screenshot the crop’d&#x2F;edited screenshot. There’s other possible issues than this bug (like iOS’s non-destructive edits by default), so it’s better to be safe than sorry.
评论 #35214926 未加载
评论 #35225035 未加载
dividuum大约 2 年前
Wait. Wouldn’t that mean that cropped images have the same file size as the uncropped version? Nobody noticed that in all those years?
评论 #35211465 未加载
PenguinRevolver大约 2 年前
A demo is available here: <a href="https:&#x2F;&#x2F;acropalypse.app&#x2F;" rel="nofollow">https:&#x2F;&#x2F;acropalypse.app&#x2F;</a>
评论 #35209027 未加载
tyingq大约 2 年前
I don&#x27;t see any sort of background at all on how it&#x27;s working. There&#x27;s metadata in the image that helps reconstruct the original? Or something about how Discord does the attachment, or?<p>Ah, one commenter offered this:<p><i>&quot;It looks like when the edits make the PNG smaller it saves the original number of bytes, overflowing its own buffer and leaving a bunch of unintended IDAT chunks to find :). Did you talk to Google about this before taking to twitter though?&quot;</i><p><a href="https:&#x2F;&#x2F;twitter.com&#x2F;Bottersnike237&#x2F;status&#x2F;1636892723012665344" rel="nofollow">https:&#x2F;&#x2F;twitter.com&#x2F;Bottersnike237&#x2F;status&#x2F;163689272301266534...</a>
评论 #35208288 未加载
zoklet-enjoyer大约 2 年前
I can crop screenshots with a Google screenshot app??? I always use Snapseed
tgsovlerkhgsel大约 2 年前
Little detail on how this works. I initially thought it&#x27;s based on thumbnails, but the high quality of the recovered image and the damage at the beginning makes me think it&#x27;s something else.
评论 #35217959 未加载
评论 #35208203 未加载