Oops, Windows’ screenshot tool may be saving stuff you cropped out, too


You know how researchers recently discovered that the Pixel’s built-in cropping tool didn’t actually get rid of the data you removed and that a little digging let you see the parts of the image that had been supposedly cut out? One of those researchers is now reporting that Microsoft’s Snipping Tool for Windows 11 as well as the Snip & Sketch tool in Windows 10 have a very similar exploit, which could mean that information people thought they’d gotten rid of is now floating around on the internet.
According to a tweet from David Buchanan, if you take a screenshot with the tool, press the save button, and then crop it and save it to the same file, the data may still be available in the file. Buchanan says you can even use pretty much the same code that let you see the rest of a Pixel screenshot to get at that data as long as you make some “minor changes.”
The vulnerability does appear to be somewhat limited in scope — Buchanan says that the exploit “requires save-crop-save,” implying that you’ll be fine if your initial screenshot only included a specific section of the screen. And while Windows 10’s Snip & Sketch tool allegedly has the same issue, Buchanan says the original Snipping Tool for Windows 10 doesn’t.
Last week, Buchanan and researcher Simon Aarons sounded the alarm about the “acropalypse” vulnerability for Pixels, pointing out that even a fix for this type of issue doesn’t make it go away. The images you made using the tool could still be out there, with the things you wanted to crop out potentially intact.
It appears that announcement spurred people to look into other screenshotting tools. Chris Blume, who chairs the working group for the PNG image format that Snipping Tool uses, helped tip Buchanan off to the issue by tweeting that Snipping Tool seems to not truncate files correctly when overwriting existing images.
Microsoft didn’t immediately respond to The Verge’s request for comment about the issue.
You know how researchers recently discovered that the Pixel’s built-in cropping tool didn’t actually get rid of the data you removed and that a little digging let you see the parts of the image that had been supposedly cut out? One of those researchers is now reporting that Microsoft’s Snipping…
Recent Posts
- OpenSSH vulnerabilities could pose huge threat to businesses everywhere
- Magic: The Gathering’s Final Fantasy sets will tell the stories of the games
- All of Chipolo’s Bluetooth trackers are discounted in sitewide sale
- Fortnite: Lawless gets first trailer highlighting the new season’s battle pass roster and the chaos of Crime City
- Chase will start blocking Zelle payments over social media
Archives
- February 2025
- January 2025
- December 2024
- November 2024
- October 2024
- September 2024
- August 2024
- July 2024
- June 2024
- May 2024
- April 2024
- March 2024
- February 2024
- January 2024
- December 2023
- November 2023
- October 2023
- September 2023
- August 2023
- July 2023
- June 2023
- May 2023
- April 2023
- March 2023
- February 2023
- January 2023
- December 2022
- November 2022
- October 2022
- September 2022
- August 2022
- July 2022
- June 2022
- May 2022
- April 2022
- March 2022
- February 2022
- January 2022
- December 2021
- November 2021
- October 2021
- September 2021
- August 2021
- July 2021
- June 2021
- May 2021
- April 2021
- March 2021
- February 2021
- January 2021
- December 2020
- November 2020
- October 2020
- September 2020
- August 2020
- July 2020
- June 2020
- May 2020
- April 2020
- March 2020
- February 2020
- January 2020
- December 2019
- November 2019
- September 2018
- October 2017
- December 2011
- August 2010