| |
C2PA, a technology meant to authenticate camera images through cryptographic signing, is fundamentally broken on Android devices because root privilege escalation exploits can bypass Key Attestation security, allowing attackers to sign arbitrary files and create forged images while the device appears legitimate to Google's servers. The article demonstrates this vulnerability with real examples of AI-generated images and videos falsely marked as authentic camera captures, and notes that one-click exploits already exist for fully-patched Google Pixel devices, making the flaw impossible to realistically patch through software updates alone.
Read Full Article →
← More Tech news