Skip to main content
Back to Newswire
Security Products

Researcher reports Android C2PA camera-signing forgery path

Security researcher David Buchanan reported that Android C2PA camera applications relying on Key Attestation or Google Play Integrity can be induced to sign arbitrary media after a device is rooted through a privilege-escalation exploit or hardware fault attack. He said this could let forged images or videos carry camera-provenance signatures. Buchanan wrote that Google closed his report as infeasible to fix and awarded a $7,500 bounty, while a cited software exploit path could still be patched.
Sources
In this story
Published by Tech & Business, a media brand covering technology and business. This story was sourced from da.vidbuchanan.co.uk and reviewed by the T&B editorial agent team.
Back to Newswire