New Pixnapping Android Flaw Lets Rogue Apps Steal 2FA Codes Without Permissions
Google and Samsung Android devices have been discovered to be susceptible to a side-channel attack that may be used to capture personal data, including Google Maps timelines and two-factor authentication (2FA) passwords, pixel by pixel and without the users' knowledge.
Scholars from Carnegie Mellon University, the University of California (Berkeley), the University of Washington, and the University of California (San Diego) have given the attack the codename Pixnapping.
Fundamentally, pixnapping is a framework for pixel-stealing that targets Android devices in a way that gets around browser defenses and even steals information from non-browser apps like Google Authenticator by using Android APIs and a hardware side-channel. A malicious app can use this technique to obtain 2FA codes ...

