Google has only partially mitigated the attack, which involves using a malicious Android app to secretly discern the two-factor codes generated by authenticator apps.
Google has assigned the issue CVE-2025-48561 (CVSS 5.5) and shipped mitigations in the September 2025 Android Security Bulletin, warning that spammy blur requests can both indicate and enable pixel ...
The adoption of new two-factor authentication (2FA) systems in 2024, particularly biometric authentication and passkeys, has delivered measurable improvements in digital payment transaction success ...