
GPU side-channel attacks (e.g., Pixnapping, CVE-2025-48561): Malicious Android apps exploit GPU rendering timing to reconstruct on-screen data (e.g., 2FA codes, messages) by analyzing how pixels are processed.
Post summary
CVE‑2025‑48561 exposes a GPU rendering timing side‑channel that malicious Android apps can exploit to read on‑screen data, indicating active exploitation in the wild.
