安全研究员 David Buchanan 于 2026 年 8 月 25 日发布研究,指出 C2PA 相机应用在 Android 平台上存在严重安全缺陷 1。C2PA 相机应用在 Android 平台上依赖 Key Attestation 和/或 Google Play Integrity 来防止用户篡改应用签署任意文件 1。然而,攻击者可通过低成本硬件故障注入或软件漏洞获取 Root 权限,进而绕过密钥证明机制伪造 C2PA 签名,使 AI 生成内容被验证为真实拍摄照片 1。Root 权限提升漏洞破坏了 Android 的 Key Attestation 安全模型和 Play Integrity,所有依赖 Android_KeyAttestation 或 Google_PlayIntegrity 的 C2PA 实现都可能存在相同漏洞 1。其中,CVE-2026-43499 漏洞允许对完全补丁的 Google Pixel 设备进行一键 Root 1。
该漏洞已提前至少 90 天报告给相关方,但 Google 最终以“Won't fix (infeasible)”的状态关闭了报告,仅向研究者支付了 7500 美元漏洞赏金 1。由于硬件故障注入和侧信道攻击不在 Google VRP 漏洞赏金计划范围内,且现有设备的硬件漏洞无法通过补丁修复,Google 尚未对旗舰 Pixel 设备发布补丁 1。相比之下,Meta 已在月初修补了 Quest 头显上的 CVE-2026-43499 LPE 漏洞 1。此外,获得 C2PA 合规计划定义的最高安全评级 Assurance Level 2 的 Google Pixel Camera 应用也受此影响 1。
Security researcher David Buchanan has uncovered a critical vulnerability in C2PA camera applications on the Android platform, allowing attackers to bypass the key attestation mechanism, forge C2PA signatures, and have AI-generated content verified as authentic photographs 1. The research was published on August 25, 2026, after the flaw had been reported to the relevant parties at least 90 days in advance 1. C2PA camera apps on Android rely on Key Attestation and/or Google Play Integrity to prevent users from tampering with the applications to sign arbitrary files, but Root privilege escalation vulnerabilities compromise Android's Key Attestation security model and Play Integrity 1.
Specifically, the CVE-2026-43499 vulnerability enables one-click rooting of fully patched Google Pixel devices, while Android devices can also achieve root access through low-cost hardware fault injection attacks 1. Because these hardware-level flaws on existing devices cannot be remediated via software patches, all C2PA implementations relying on Android_KeyAttestation or Google_PlayIntegrity are potentially susceptible to the exact same issue 1. Although the Google Pixel Camera app holds Assurance Level 2, the highest security rating defined by the C2PA compliance program, Google closed the report with a "Won't fix (infeasible)" status and has yet to release a patch for its flagship Pixel devices 1.
Google paid the researcher a $7,500 bug bounty, even though hardware fault injection and side-channel attacks fall outside the scope of the Google VRP bug bounty program 1. In contrast to Google's inaction on its flagship phones, Meta has already patched the CVE-2026-43499 local privilege escalation vulnerability on its Quest headsets earlier this month 1.
评论
还没有评论,欢迎留下第一条。