Software

OSes

Microsoft scrambles to fix Windows 11 'aCropalypse' privacy-battering bug

All your previously Snipping Tool cropped images aren't, basically


Updated Microsoft is said to be preparing to fix the high-profile "aCropalypse" privacy bug in its Snipping Tool for Windows 11.

Users can remove sensitive information or some other parts of photos, screenshots, and other images by cropping them using the Snipping Tool app. The problem is that for the Windows 11 app – as well as Microsoft's Snip & Sketch cropping tool in Windows 10 – the file of the cropped image still includes the cropped out portions, which can be recovered and viewed.

A similar flaw was found in Google's Markup image-editing app for its Pixel smartphones. According to reverse engineers Simon Aarons and David Buchanan – who named the bug aCropalyse – the problem affects Pixel smartphones since 2018, when the 3 series came out. Google patched its code to avoid leaking cropped areas of images.

Then this week, Buchanan confirmed that the Windows Snipping Tool and Snip & Sketch software had the same issue. If a user cropped a photo or other image using the software and then saved the edited image over the original file, that file still contains the cropped-out portion. The area isn't visible when viewing the image using normal tools, but the data is still there in the file, and can be restored and viewed using appropriate recovery software.

Steven Murdoch, a professor of security engineering at the UK's University College London, shared some thoughts here on the underlying issue within Windows, specifically its latest Save File API, which he described as "defective by design."

We're saved .. soon!

A Windows Insider who goes by the handle XenoPanther observed that Microsoft may have fixed the problem already. The Windows giant created version 11.2302.20.0 of the Snipping Tool app – the current stable version is 11.2302.4.0 – and is releasing it in the Windows Insider Canary channel for testing.

The Register has asked Microsoft for a response and will add it to the story if one comes back.

It's unclear when Microsoft intends to release the updated Snipping Tool app to all users – or if a fix is coming for the flaw in Windows 10 – though the quick reaction to the initial report indicates that Redmond is eager to get this sorted quickly.

Meanwhile, if you've used Microsoft's code to crop your snaps and then shared them on, be aware someone with a copy of them might be able to recover the lopped-off portions. ®

Updated at 13.31 BST on March 27 2023 to add:

Microsoft late last week outlined fixes for both the Snipping Tool app in Windows 11 and Snip and Sketch in Windows 10.

"We have released a security update for these tools via CVE-2023-28303. We recommend customers apply the update," a Microsoft spokesperson told The Register.

In its note, Microsoft said that while the severity level for the vulnerability is low, it's still a problem. "When an existing image is partially overwritten, an attacker may be able to recover parts of the original image through the use of a special tool," the vendor wrote.

The update fixing the problem in Snipping Tool is contained in app versions 11.2302.20.0 and later. For Snip and Sketch, it's app versions 10.2008.3001.0 and later.

Send us news
54 Comments

Google formally accuses monopolist Microsoft of trapping people in its cloud

Fight! Fight! Fight!

Microsoft investigating bug in Windows 11 File Explorer that makes the CPU hangry

On the other hand, some old settings are set for a comeback

Google accused of ripping off advertisers with video ads no one saw. Now, the expert view

Web giant also hits back ... right as YouTube steps up war on advert blockers

Microsoft rethinks death sentence for Windows Mail and Calendar apps

Shifting those duties to Outlook set for next year – well, maybe

Microsoft remembers it was going to bring Windows 11 to HoloLens

While Apple has Vision Pro, Redmond's taking vision slow?

Google bug bounties inch closer to Microsoft's payouts

Chocolate Factory paid a record $12m in 2022

Microsoft's Activision fight with FTC turned up a Blizzard of docs: Here's your summary

Windows PCs in the cloud, spending Sony out of business, mobile woes, and more – and the files to read

Google accused of urging Android devs to mislabel apps to get forbidden kids ad data

Getting around the rules was as simple as not declaring software was 'intended for children', lawsuit states

Google asks websites to kindly not break its shiny new targeted-advertising API

Tech tweaked ahead of rollout in July, Mozilla and Apple still not interested

At last, Microsoft lets Windows 11 share files with Android apps

Android and Microsoft sitting in a tree K-I-S-S-I-N-G! But not too much

Where's my money?! Now USA Today publisher sues Google over online advertising

That ads to hurt

This Windows update is snarling up some endpoint security tools

Malwarebytes and Trellix upgrades to the rescue