{"@context":"https://schema.org","@type":"NewsArticle","generatedAt":"2026-08-26T16:41:05.375Z","headline":"C2PA相机经不起现实的考验：Android端可被root攻击伪造签名","description":"安全研究员David Buchanan指出，C2PA相机认证在Android平台上可被攻破。通过root权限提升漏洞（如CVE-2026-43499），攻击者可利用StrongBox硬件签名任意数据，伪造C2PA签名图像和视频，且无需硬件攻击。该问题无法通过常规补丁修复，已提前90天向相关方报告。 🔗 阅读原文 via AIHOT · https://aihot.virxact.com/items/cmta6v56y03ytroj25ggn7rlo","url":"https://www.aioga.com/news/cmta6v56y03ytroj25ggn7rlo/","mainEntityOfPage":"https://www.aioga.com/news/cmta6v56y03ytroj25ggn7rlo/","datePublished":"2026-08-26T14:05:27.000Z","dateModified":"2026-08-26T14:05:27.000Z","inLanguage":"zh-CN","publisher":{"@type":"NewsMediaOrganization","name":"Aioga","url":"https://www.aioga.com"},"citation":["https://www.da.vidbuchanan.co.uk/blog/android-c2pa.html","https://aihot.virxact.com/items/cmta6v56y03ytroj25ggn7rlo"],"canonicalUrl":"https://www.aioga.com/news/cmta6v56y03ytroj25ggn7rlo/","directAnswer":{"@type":"Answer","text":"安全研究员David Buchanan称，取得Android设备root权限后，攻击者可调用StrongBox为任意数据签名，进而伪造带有C2PA签名的图像和视频；摘要还称该问题已提前90天报告相关方。","url":"https://www.aioga.com/news/cmta6v56y03ytroj25ggn7rlo/","dateCreated":"2026-08-26T14:05:27.000Z","author":{"@type":"Organization","@id":"https://www.aioga.com/authors/aioga-editorial/#editorial-team","name":"Aioga Editorial Team","url":"https://www.aioga.com/authors/aioga-editorial/"}},"evidence":[{"@type":"CreativeWork","name":"da.vidbuchanan.co.uk source article","url":"https://www.da.vidbuchanan.co.uk/blog/android-c2pa.html","datePublished":"2026-08-26T14:05:27.000Z","provider":{"@type":"Organization","name":"da.vidbuchanan.co.uk","url":"https://www.da.vidbuchanan.co.uk/blog/android-c2pa.html"}},{"@type":"CreativeWork","name":"AIHot archive record","url":"https://aihot.virxact.com/items/cmta6v56y03ytroj25ggn7rlo","datePublished":"2026-08-26T14:05:27.000Z","provider":{"@type":"Organization","name":"AIHot","url":"https://aihot.virxact.com/items/cmta6v56y03ytroj25ggn7rlo"}}],"aggregationSource":"Hacker News 热门（buzzing.cc 中文翻译","originalPublisher":{"name":"da.vidbuchanan.co.uk","url":"https://www.da.vidbuchanan.co.uk/blog/android-c2pa.html"},"geoDeepAnswer":null,"article":{"id":"cmta6v56y03ytroj25ggn7rlo","slug":"cmta6v56y03ytroj25ggn7rlo","url":"https://www.aioga.com/news/cmta6v56y03ytroj25ggn7rlo/","title":"C2PA相机经不起现实的考验：Android端可被root攻击伪造签名","title_en":"","summary":"安全研究员David Buchanan指出，C2PA相机认证在Android平台上可被攻破。通过root权限提升漏洞（如CVE-2026-43499），攻击者可利用StrongBox硬件签名任意数据，伪造C2PA签名图像和视频，且无需硬件攻击。该问题无法通过常规补丁修复，已提前90天向相关方报告。 🔗 阅读原文 via AIHOT · https://aihot.virxact.com/items/cmta6v56y03ytroj25ggn7rlo","source":"Hacker News 热门（buzzing.cc 中文翻译","sourceUrl":"https://www.da.vidbuchanan.co.uk/blog/android-c2pa.html","aiHotUrl":"https://aihot.virxact.com/items/cmta6v56y03ytroj25ggn7rlo","publishedAt":"2026-08-26T14:05:27.000Z","category":"行业动态","score":72,"selected":true,"articleBody":["By David Buchanan (aka retr0id), 25 th August 2026","You might have heard that C2PA：https://c2pa.org/ is a technology that will miraculously save us from rampant AI forgeries, by having cameras cryptographically sign the images they capture. Hooray for cryptography：https://www.aumasson.jp/murphy.html!","Sorry. That's not going to work. There's a lot going on here, so I'll try to get to the point as quickly as possible:","Being able to sign arbitrary files breaks C2PA's trust model：https://spec.c2pa.org/specifications/specifications/2.4/specs/C2PA_Specification.html#_trust_model.","Root privilege escalation exploits break Android's Key Attestation security model, and Play Integrity likewise.","Android devices can be rooted via low-cost hardware fault injection attacks：https://www.da.vidbuchanan.co.uk/blog/dram-emfi.html.","Hardware vulnerabilities in existing devices cannot be patched (there's nuance here, discussed later).","Therefore, C2PA on the Android platform is broken, in a way that cannot be realistically patched .","None of the above is \"0day\", and has been reported to the relevant parties at least 90 days ago (but anyone with their head screwed on should have seen it coming, as many have).","But wait, there's more! Thanks in part to LLMs, root LPEs are coming out faster than Google can ship patches. At time of writing, one-click root exploits：https://github.com/alex193a/Root-My-Pixel exist in-the-wild for fully-patched Google Pixel devices (via CVE-2026-43499：https://nvd.nist.gov/vuln/detail/CVE-2026-43499). With these, anyone can produce C2PA forgeries without requiring hardware attacks. Later in this article, I'll provide instructions for doing so.","As you can see, I'm focusing on Android here. I'll let Google explain why：https://blog.google/security/pixel-android-trusted-images-c2pa-content-credentials/:","The Pixel Camera app achieved Assurance Level 2 ：https://github.com/c2pa-org/conformance-public/blob/main/conforming-products/conforming-products-list.json, the highest security rating currently defined：https://github.com/c2pa-org/conformance-public/blob/main/docs/current/C2PA%20Generator%20Product%20Security%20Requirements.pdf by the C2PA Conformance Program. Assurance Level 2 for a mobile app is currently only possible on the Android platform .","i.e. I'm attacking the \"strongest\" implementation, just to make a point. Here's an AI-generated slop image, which C2PA says is a real unedited photograph straight out of the Pixel Camera app: (Hover to un-blur, click to \"verify\" it)","：https://verify.contentauthenticity.org/?source=https%3A%2F%2Fretr0.id%2Fstuff%2Fnocors%2Fblog_frog.jpg","And, here's a Youtube video：https://www.youtube.com/watch?v=Uqpqw91pcac that the infobox says was \"captured with a camera\" (spoiler alert: it wasn't).","Edit, 2026-08-25T19:12:16Z: Google appears to have removed the \"Captured with a camera\" section from the video description, presumably manually. That doesn't achieve much—read on to learn how to sign your own media. Also I swapped out the URL for another one. The forgeries will continue until morale improves.","By the way, Apple is rumoured：https://www.macrumors.com/2026/08/10/ios-27-apple-reference-image/ to be working on their own media provenance solution, but it doesn't exist yet. I'll let you know what I think of it, when it does. I suspect their vertical integration will give them a significant advantage, which might shift the lowest-hanging-fruit attacks into the optical domain (taking pictures of screens, etc.)","Anyway, let's get into the details.","Attestation only attests certain things, including:","The \"normal\" way to root an Android device is to unlock the bootloader and flash a modified firmware image, which forces a factory reset of the device in the process. Attestation will flag that the bootloader is unlocked, and Google will refuse to provision C2PA keys to your device (and Netflix won't serve you high-res content, your banking app won't work, etc. etc.)","So far, so good (if you're into that kind of thing.)","However, if you root a device via an exploit, the attestation mechanism has no reliable way to \"notice\". The bootloader is still locked, the AVB keys are unmodified, and the device is still running whatever security update it booted with initially. Now Google's servers will happily provision keys to a compromised device.","The theory behind the design of the attestation mechanism is that known software LPEs should be patched, and then the Relying Party (the entity verifying the attestation report) can require that users install the updates, and then the updated device can no longer be LPE'd.","CVE-2026-43499：https://nvd.nist.gov/vuln/detail/CVE-2026-43499 is proof that timely patches are not always available, but let's give everyone the benefit of the doubt and pretend that public exploits for unpatched bugs never exist. There are two remaining problems:","Any moderately-well-funded entity, from governments to mobile forensics companies, can build a stockpile of private exploits (and so they do). These are exactly the groups you don't want to be forging C2PA signatures.","Low-cost hardware exploits exist, regardless of patch level.","Initially, I used a hardware attack. It was a continuation of my earlier research: Can You Get Root With Only a Cigarette Lighter?：https://www.da.vidbuchanan.co.uk/blog/dram-emfi.html","I was going to write about it in-depth here, but frankly the software-only exploit：https://github.com/alex193a/Root-My-Pixel paths：https://github.com/BuSung-dev/Root-My-Galaxy stole my thunder. Software exploits are much more convenient when they exist, so I'll save the full hardware details for another time. There's no rush, since the hardware exploits can't be patched, for the most part.","If you'd like to reproduce my findings today, I recommend the Root My Pixel：https://github.com/alex193a/Root-My-Pixel tool. (Note: while it supports the latest August security updates of most Pixel devices today, you'll need to build from main to enable that support. I've personally tested on Pixel 8a and 9a.)","After getting root, the rest of the attack is just plumbing. I made a tool to facilitate this: keystork：https://github.com/DavidBuchanan314/keystork. Keystork has a client/server architecture, allowing client code to perform arbitrary operations against the KeyStore API：https://developer.android.com/reference/java/security/KeyStore, while impersonating any installed app. The \"server\" ( keystorkd ) runs on a rooted device, and the client is anything that can speak the wire protocol I made up (transported by default via a unix domain socket forwarded over ADB). The reference client is a python library with a corresponding CLI interface, but in theory Android apps could talk to it, Shizuku：https://github.com/rikkaapps/shizuku-style (although you'd want to build an auth/permissions layer first).","Here's a \"sign any image\" PoC script, against the Pixel Camera app: https://gist.github.com/DavidBuchanan314/fa0ffdaaaa31594e6a511118c1cea1e0：https://gist.github.com/DavidBuchanan314/fa0ffdaaaa31594e6a511118c1cea1e0","While software exploits can and will be patched (eventually), the hardware exploits are forever. Or are they?","In theory yes, in practice not really.","My initial strategy (flipping bits in PTEs) still works on Pixel devices today. However, it does not work on Samsung devices!","I did some of my initial tests on a Samsung A07 device (because they're cheap). The exploit worked at the time, but after a security update it stopped working (I think the timing was a coincidence). The update enabled Samsung's \"RKP：https://docs.samsungknox.com/admin/fundamentals/whitepaper/samsung-knox-mobile-security/system-security/real-time-kernel-protection/\" mitigation (Real-time Kernel Protection, not to be confused with Remote Key Provisioning...)","Among other things, Samsung's mitigations use an EL2 hypervisor to apply additional protections to certain memory regions (a bit like Microsoft's HVCI：https://connormcgarr.github.io/hvci/). I can still use hardware exploits to flip bits in PTEs, but even if I map a PTE into userspace via glitching, EL2 won't let me overwrite it (which was an essential part of my exploit, as initially designed).","I have several plans for alternate strategies to work around Samsung's mitigations, but I haven't gotten around to implementing them yet. One of my alternate strategies should work even in the presence of hardware memory encryption. Once I get it working, I'd like to package this strategy up into a \"universal Android hardware root\" tool—watch this space? (I would also like to pop HVCI to mess with anti-cheat, watch that space, too.)","At the hardware level, several solutions exist that treat external DRAM as completely untrusted, thus mitigating any kind of bus faulting attack, in theory at least. Examples include Intel MEE：https://eprint.iacr.org/2016/204.pdf, and Apple's SEP Memory Protection Engine：https://support.apple.com/en-gb/guide/security/sec59b0b31ff/web#secb8d5e5708. However, these solutions are not performant enough to realistically run the whole Android linux kernel within (which is why Apple only uses it to protect SEP and not the main AP, and Intel dropped the feature entirely in newer SGX revisions, leading to attacks like Battering RAM：https://batteringram.eu/).","Even with the best hardware-level mitigations, fixing C2PA on Android is going to involve completely rearchitecting the software stack. The entire image processing pipeline, including all the fancy AI stuff, would need to run inside a secure enclave with strong hardware memory protection.","I don't think Google is going to do all that, which is probably why they closed my report with status \"Won't fix (infeasible)\". It just doesn't make sense to do all that rearchitecting, when you still can't stop \"picture of screen\" style attacks.","By the way, despite the WONTFIX resolution, Google chose to award me a $7500 bounty for the submission:","Thank you for submitting your report. While hardware glitching and side channel attacks are out of scope for our bug bounty program, our security team found your findings valuable, and the data you provided will help us improve future iterations of the product.","I wasn't expecting a bounty (I knew it was formally out-of-scope), so it was a nice surprise. It'll cover all the devices I bricked during my research. But it's worth noting:","The most obvious (to me) C2PA attack vector is out of scope for Google's VRP. Thus, the VRP does not meaningfully protect Android C2PA implementations.","I've been focusing on the Pixel Camera app here, but there are several other \"C2PA Camera\" apps on Android. All those I've investigated rely on either Key Attestation or Play Integrity for their security. They are all broken in the same way, except they're not exclusive to Google Pixel devices. This means you don't need to root a Pixel device, you can pick the cheapest and most vulnerable device in the whole Android ecosystem to run your exploit on.","They are all victims of Google's misleading marketing claims regarding the effectiveness of their platform's security. You can find a full list of \"Conformant\" C2PA implementations here：https://github.com/c2pa-org/conformance-public/blob/main/conforming-products/conforming-products-list.json (All that include Android_KeyAttestation or Google_PlayIntegrity in their attestationMethods list are likely vulnerable)","Outside of C2PA, I've been having fun using my hardware glitching strategy to root a wide variety of Android devices, including an Amazon Fire TV stick and a Meta Quest 3s VR headset (again, I will probably write more about this later!)","Aside: Meta already patched the CVE-2026-43499 LPE on Quest headsets, near the start of the month, to stop people from cheating in VR video games. It's absolutely bonkers to me that Google has not issued a patch for even their flagship Pixel devices yet.","While I've taken a recent foray into the C2PA ecosystem, Dr. Neal Krawetz of Hacker Factor：https://www.hackerfactor.com/blog/ has been sounding the alarm about it for years. His writing was my introduction to the topic, and he's been very helpful in discussing things with me, as well as helping coordinate vulnerability disclosures.","You can read his takes on these vulnerabilities here：https://www.hackerfactor.com/blog/index.php?/archives/1102-C2PA-and-Pixel-Glitter-Milk.html.","Thank you also to the Provenance and Authenticity Standards Assessment Working Group：https://cisa.umbc.edu/pasawg/ (PASAWG), who are likewise researching the effectiveness of C2PA.","While preparing my PoC for publication, I had a fun \"but what if?\" thought. Pulling on that thread led me to a private key disclosure vulnerability. I reported it to Google two days ago, and they seem to have patched it yesterday (this is why I prefer hardware attacks, patches ruin the fun). I'll probably write more about it in the future.","This is where I would paste in a Pixel Camera C2PA private key and corresponding certificate chain, if I wasn't a coward. But I decided not to. If you're a journalist who'd like a peek, let me know.","I assume Google has revoked this particular key by now (I included it in my report to them). However most C2PA verification tools do not check for revocation. I'm sure they'll fix that soon, too.","All blog content produced by thinking meat：https://web.mit.edu/people/dpolicar/writing/prose/text/thinkingMeat.html, unless noted otherwise.","Homepage：/ - Blog Index：/blog/ - RSS：rss.xml","This blog is part of the Haunted Webring：https://pixeldreams.tokyo/cgi-bin/webring.cgi","：https://pixeldreams.tokyo/cgi-bin/webring.cgi?after=https%3A%2F%2Fwww.da.vidbuchanan.co.uk%2Fblog%2F","A word from our unofficial sponsors:"],"articleImages":[{"sourceUrl":"https://retr0.id/stuff/nocors/blog_frog.jpg","alt":"","afterParagraph":12,"url":"/media/articles/cmta6v56y03ytroj25ggn7rlo/9a6f400c9a21b0c6.jpg"},{"sourceUrl":"https://www.da.vidbuchanan.co.uk/blog/static/fc0850fe2e41f8187f59071224878c5da2e321c8206c6f9c8a983e9e34066266.jpg","alt":"","afterParagraph":14,"url":"/media/articles/cmta6v56y03ytroj25ggn7rlo/dcf44c8dc80e350b.jpg"}],"mediaStatus":"ok","articleBodyZh":["作者：David Buchanan（又名 retr0id），2026 年 8 月 25 日","你可能听说过 C2PA：https://c2pa.org/ 是一种神奇的技术，它可以通过让相机对拍摄的图像进行加密签名，从而拯救我们免受肆虐的 AI 伪造。为加密技术欢呼吧：https://www.aumasson.jp/murphy.html！","抱歉，这行不通。这里有很多情况需要考虑，所以我会尽量快地切入正题：","能够签名任意文件会破坏 C2PA 的信任模型：https://spec.c2pa.org/specifications/specifications/2.4/specs/C2PA_Specification.html#_trust_model。","Root 权限提升漏洞会破坏 Android 的密钥认证安全模型，Play Integrity 也是如此。","Android 设备可以通过低成本的硬件故障注入攻击被 Root：https://www.da.vidbuchanan.co.uk/blog/dram-emfi.html。","现有设备的硬件漏洞无法修补（这里有细微差别，稍后会讨论）。","因此，Android 平台上的 C2PA 是破碎的，无法现实地修补。","以上内容都不是“0day”，并且已在至少 90 天前报告给相关方（但任何头脑清楚的人都应该早有预见，正如许多人已经看到的那样）。","但等一下，还有更多！部分由于大语言模型（LLM）的原因，Root 权限提升漏洞的出现速度比 Google 推送补丁的速度还快。在撰写本文时，一击 Root 漏洞：https://github.com/alex193a/Root-My-Pixel 已经存在于完全打好补丁的 Google Pixel 设备上（通过 CVE-2026-43499：https://nvd.nist.gov/vuln/detail/CVE-2026-43499）。利用这些漏洞，任何人都可以在不需要硬件攻击的情况下生成 C2PA 伪造品。本文后面，我将提供操作指南。","如你所见，我在这里主要关注 Android。我会让 Google 来解释原因：https://blog.google/security/pixel-android-trusted-images-c2pa-content-credentials/:","Pixel Camera 应用程序实现了保证级别 2：https://github.com/c2pa-org/conformance-public/blob/main/conforming-products/conforming-products-list.json，由 C2PA 合规计划定义的最高安全等级：https://github.com/c2pa-org/conformance-public/blob/main/docs/current/C2PA%20Generator%20Product%20Security%20Requirements.pdf。目前，移动应用达到保证级别 2 仅可能在 Android 平台上实现。","也就是说，我正在攻击“最强”实现，仅仅是为了说明问题。这是一张 AI 生成的模糊图片，C2PA 说它是直接来自 Pixel Camera 应用的真实未经编辑的照片：（悬停以取消模糊，点击以“验证”）","：https://verify.contentauthenticity.org/?source=https%3A%2F%2Fretr0.id%2Fstuff%2Fnocors%2Fblog_frog.jpg","这是一个 Youtube 视频：https://www.youtube.com/watch?v=Uqpqw91pcac，信息框显示“用相机拍摄” （剧透：实际上并非如此）。","编辑，2026-08-25T19:12:16Z：Google 似乎已从视频描述中手动删除了“用相机拍摄”部分。不过这作用不大——继续阅读，了解如何给自己的媒体签名。我也换了一个 URL。伪造行为会继续，直到士气恢复。","顺便提一下，据传 Apple 正在：https://www.macrumors.com/2026/08/10/ios-27-apple-reference-image/ 开发自己的媒体来源解决方案，但目前尚不存在。当它出现时，我会告诉你我的看法。我怀疑他们的垂直整合会给他们带来显著优势，这可能会把最容易的攻击转向光学领域（拍摄屏幕等）。","无论如何，让我们深入了解细节。","证明仅对某些事项作出证明，包括：","安卓设备的“正常” ROOT 方式是解锁 bootloader 并刷入修改后的固件镜像，这个过程会强制设备执行出厂重置。认证会标记 bootloader 已解锁，Google 将拒绝向你的设备提供 C2PA 密钥（Netflix 不会提供高清内容，你的银行应用无法使用，等等）。","到目前为止，一切顺利（如果你喜欢这种玩法的话）。","然而，如果你通过利用漏洞获取设备的 root 权限，认证机制没有可靠的方式可以“察觉”。引导加载程序仍然是锁定的，AVB 密钥未被修改，设备仍然运行最初启动时的安全更新。现在，谷歌的服务器会愉快地向已被攻破的设备提供密钥。","认证机制设计背后的理论是，已知的软件本地特权提升（LPE）漏洞应当被修补，然后依赖方（验证认证报告的实体）可以要求用户安装更新，更新后的设备就不再容易受到 LPE 攻击。","CVE-2026-43499：https://nvd.nist.gov/vuln/detail/CVE-2026-43499 证明及时的补丁并不总是可用，但让我们给大家留个好处的怀疑，假装未修补漏洞的公开漏洞从不存在。还有两个剩余问题：","任何资金较充足的实体，从政府到移动取证公司，都可以建立私人漏洞库存（而且他们确实这样做）。这些正是你不希望伪造 C2PA 签名的群体。","低成本的硬件漏洞存在，无论补丁级别如何。","最初，我使用了硬件攻击。这是我早期研究的延续：你仅用打火机能获取 root 吗？：https://www.da.vidbuchanan.co.uk/blog/dram-emfi.html","我本打算在这里深入讨论，但坦率地说，纯软件漏洞：https://github.com/alex193a/Root-My-Pixel 途径：https://github.com/BuSung-dev/Root-My-Galaxy 抢了我的风头。软件漏洞存在时要方便得多，所以我会把完整的硬件细节留到以后再说。没有必要着急，因为硬件漏洞在大多数情况下是无法修补的。","如果你今天想复现我的发现，我推荐使用 Root My Pixel：https://github.com/alex193a/Root-My-Pixel 工具。（注意：虽然它今天支持大多数 Pixel 设备的最新八月安全更新，但你需要从 main 构建以启用该支持。我个人在 Pixel 8a 和 9a 上进行了测试。）","根基化后，剩下的攻击就是管道。我做了一个工具来实现这一点：keystork：https：//github.com/DavidBuchanan314/keystork。Keystork 采用客户端/服务器架构，允许客户端代码在 KeyStore API 下执行任意操作：https：//developer.android.com/reference/java/security/KeyStore，同时模拟任何已安装的应用。“服务器”（keystorkd）运行在已root的设备上，客户端是任何能使用我设计的有线协议的设备（默认通过Unix域套接字通过ADB转发传输）。参考客户端是一个带有相应CLI接口的Python库，但理论上Android应用可以与它通信，Shizuku：https：//github.com/rikkaapps/shizuku-style（不过你最好先构建一个授权/权限层）。","这里有一个针对Pixel Camera应用的“签名任意图片”PoC脚本：https://gist.github.com/DavidBuchanan314/fa0ffdaaaa31594e6a511118c1cea1e0:https://gist.github.com/DavidBuchanan314/fa0ffdaaaa31594e6a511118c1cea1e0","虽然软件漏洞利用可以且最终会被修补，但硬件漏洞利用是永无止境的。或者说，真的是这样吗？","理论上是，但实际上并不完全是。","我最初的策略（在PTE中切换位元）至今在Pixel设备上仍然有效。不过，它在三星设备上无法使用！","我最初在三星A07设备上做了一些测试（因为它们便宜）。漏洞当时有效，但安全更新后停止工作（我觉得时间点恰巧）。此次更新启用了三星的“RKP：https：//docs.samsungknox.com/admin/fundamentals/whitepaper/samsung-knox-mobile-security/system-security/real-time-kernel-protection/”缓解措施（实时内核保护，不要与远程密钥配置混淆......）","三星的缓解措施之一是使用EL2虚拟机监控程序对某些内存区域施加额外保护（有点像Microsoft的HVCI：https：//connormcgarr.github.io/hvci/）。我仍然可以用硬件漏洞来翻转PTE中的位，但即使我通过故障映射PTE到用户空间，EL2也不允许我覆盖它（这是我最初设计漏洞的关键部分）。","我有几个备用策略的计划，可以绕过三星的缓解措施，但我还没有实施它们。其中一个备用策略即使在存在硬件内存加密的情况下也应该有效。一旦我让它工作，我想把这个策略打包成一个“通用 Android 硬件 root”工具——敬请期待？（我也想攻击 HVCI 来玩反作弊，也可以关注这个。）","在硬件层面，存在几种解决方案将外部 DRAM 视为完全不可信，从而理论上缓解任何类型的总线故障攻击。示例包括 Intel MEE：https://eprint.iacr.org/2016/204.pdf，以及 Apple 的 SEP 内存保护引擎：https://support.apple.com/en-gb/guide/security/sec59b0b31ff/web#secb8d5e5708。然而，这些解决方案的性能不足以现实地运行整个 Android Linux 内核（这也是苹果只用它来保护 SEP 而不是主 AP，且英特尔在新版 SGX 中完全放弃该功能，导致了像 Battering RAM：https://batteringram.eu/ 这样的攻击）。","即使有最好的硬件级缓解措施，要在 Android 上修复 C2PA，也将涉及完全重构软件堆栈。整个图像处理管线，包括所有炫酷的 AI 功能，都需要在带有强大硬件内存保护的安全区域中运行。","我认为谷歌不会做这些，这可能就是他们以“不会修复（不可行）”的状态关闭我的报告的原因。进行所有这些重构是没有意义的，因为你仍然无法阻止“屏幕截图”类型的攻击。","顺便说一句，尽管是 WONTFIX 的结论，谷歌仍选择给我的提交奖励了 7500 美元的赏金：","感谢您提交报告。虽然硬件故障攻击和侧信道攻击不在我们的漏洞赏金计划范围内，但我们的安全团队认为您的发现很有价值，您提供的数据将帮助我们改进产品的未来版本。","我本不期望得到赏金（我知道从形式上讲不在范围内），所以这是一个惊喜。这将涵盖我在研究期间损坏的所有设备。但值得注意的是：","对我来说，最明显的 C2PA 攻击向量超出了 Google VRP 的范围。因此，VRP 并不能真正保护 Android 上的 C2PA 实现。","我这里一直关注的是 Pixel Camera 应用，但在 Android 上还有其他几个“C2PA Camera”应用。我调查过的所有这些应用都依赖于 Key Attestation 或 Play Integrity 来保障安全。它们都是以相同的方式存在漏洞，不过这些漏洞不仅限于 Google Pixel 设备。这意味着你不需要 root 一台 Pixel 设备，你可以选择整个 Android 生态系统中最便宜、最脆弱的设备来运行你的漏洞利用。","它们都是 Google 关于其平台安全有效性的误导性宣传的受害者。你可以在这里找到完整的“符合规范” C2PA 实现列表：https://github.com/c2pa-org/conformance-public/blob/main/conforming-products/conforming-products-list.json（所有在 attestationMethods 列表中包含 Android_KeyAttestation 或 Google_PlayIntegrity 的实现很可能存在漏洞）","在 C2PA 之外，我一直在使用我的硬件故障利用策略来 root 各种 Android 设备，包括 Amazon Fire TV stick 和 Meta Quest 3 VR 头显（我可能会在以后写更多关于此的内容！）","顺便说一下：Meta 已经在月初修补了 Quest 头显上的 CVE-2026-43499 本地提权漏洞，以阻止人们在 VR 视频游戏中作弊。我觉得完全不可思议的是，Google 甚至还没有为其旗舰 Pixel 设备发布修补程序。","虽然我最近才涉足 C2PA 生态系统，但 Hacker Factor 的 Neal Krawetz 博士（https://www.hackerfactor.com/blog/）多年来一直在发出警告。他的文章是我接触这一主题的起点，他在与我讨论问题以及协助漏洞披露协调方面都非常有帮助。","你可以在这里阅读他对这些漏洞的看法：https://www.hackerfactor.com/blog/index.php?/archives/1102-C2PA-and-Pixel-Glitter-Milk.html。","同时感谢来源和真实性标准评估工作组：https://cisa.umbc.edu/pasawg/（PASAWG），他们也在研究C2PA的有效性。","在准备我的 PoC 发布时，我有一个有趣的“如果……会怎样？”的想法。顺着这个思路，我发现了一个私钥泄露漏洞。我两天前向谷歌报告了这个问题，他们似乎在昨天已经修补了（这就是为什么我更喜欢硬件攻击，补丁会破坏乐趣）。我可能将来会写更多相关内容。","如果我不是胆小鬼，这里我本会贴出一份 Pixel Camera C2PA 私钥及相应的证书链。但我决定不这么做。如果你是想看一眼的记者，请告诉我。","我假设谷歌现在已经吊销了这把私钥（我在报告中已经包含了它）。然而，大多数 C2PA 验证工具并不检查撤销状态。我相信他们很快也会修复这个问题。","除非另有说明，所有由 Thinking Meat 创作的博客内容可在以下网址查看：https://web.mit.edu/people/dpolicar/writing/prose/text/thinkingMeat.html。","首页：/ - 博客索引：/blog/ - RSS：rss.xml","此博客是幽灵网站环的一部分：https://pixeldreams.tokyo/cgi-bin/webring.cgi","：https://pixeldreams.tokyo/cgi-bin/webring.cgi?after=https%3A%2F%2Fwww.da.vidbuchanan.co.uk%2Fblog%2F","来自我们非官方赞助商的一句话："],"translationStatus":"translated","bodyOrigin":"source-page","editorial":{"summary":"安全研究员David Buchanan称，取得Android设备root权限后，攻击者可调用StrongBox为任意数据签名，进而伪造带有C2PA签名的图像和视频；摘要还称该问题已提前90天报告相关方。","background":"C2PA依赖相机对所捕获内容进行加密签名，并以此建立内容来源信任。正文指出，任意文件签名能力会破坏其信任模型，而root提权漏洞也会影响Android密钥证明与Play Integrity的安全模型。","viewpoint":"Aioga判断，这项研究质疑的并非密码学签名本身，而是签名密钥所在设备能否持续保持可信。若系统被提权后仍可调用硬件签名能力，验证者看到有效签名也未必能据此确认内容真实。","implications":"可能受到影响的是将Android端C2PA签名直接等同于真实拍摄证明的应用场景。正文认为，既有设备的硬件漏洞无法现实地通过常规方式修补，但具体影响范围、适用机型及利用条件仍需更多材料确认。","nextStep":"值得关注相关方在披露后的回应、CVE-2026-43499细节、受影响设备范围及缓解方案。采用C2PA的机构可进一步核查验证流程是否仅依赖签名有效性，并区分来源声明与内容真实性判断。","evidenceRefs":["title","summary","articleBody","source"],"status":"published","aiGenerated":true,"autoApproved":true,"generatedBy":"aioga-editorial:gpt-5.6-sol","reviewedBy":"aioga-editorial-review:gpt-5.6-sol","generatedAt":"2026-08-26T14:56:45.513Z","sourceHash":"0998a8e728a3b3ec","review":{"approved":true,"groundedness":93,"clarity":91,"duplicationRisk":12,"blockingIssues":[],"notes":["“取得Android设备root权限后可调用StrongBox为任意数据签名”主要依据来源摘要，正文摘录未展开StrongBox细节；如需严格仅按正文审核，可补充对应原文段落。","“采用C2PA的机构可进一步核查验证流程……”属于合理的实践建议，不是来源事实断言。"]},"validation":{"passed":true,"mode":"ai-auto","revisions":0,"checks":["schema","length","source-attribution","low-source-overlap","no-html","independent-ai-review"]}},"tags":["行业动态","Hacker News 热门（buzzing.cc 中文翻译）"],"translations":{"zh-CN":{"title":"C2PA相机经不起现实的考验：Android端可被root攻击伪造签名","summary":"安全研究员David Buchanan指出，C2PA相机认证在Android平台上可被攻破。通过root权限提升漏洞（如CVE-2026-43499），攻击者可利用StrongBox硬件签名任意数据，伪造C2PA签名图像和视频，且无需硬件攻击。该问题无法通过常规补丁修复，已提前90天向相关方报告。 🔗 阅读原文 via AIHOT · https://aihot.virxact.com/items/cmta6v56y03ytroj25ggn7rlo","category":"行业动态","source":"da.vidbuchanan.co.uk","aggregationSource":"Hacker News 热门（buzzing.cc 中文翻译","pageTitle":"C2PA相机经不起现实的考验：Android端可被root攻击伪造签名 - Aioga AI资讯","description":"安全研究员David Buchanan指出，C2PA相机认证在Android平台上可被攻破。通过root权限提升漏洞（如CVE-2026-43499），攻击者可利用StrongBox硬件签名任意数据，伪造C2PA签名图像和视频，且无需硬件攻击。该问题无法通过常规补丁修复，已提前90天向相关方报告。 🔗 阅读原文 via AIHOT · https://aih...","url":"https://www.aioga.com/news/cmta6v56y03ytroj25ggn7rlo/","articleBody":["作者：David Buchanan（又名 retr0id），2026 年 8 月 25 日","你可能听说过 C2PA：https://c2pa.org/ 是一种神奇的技术，它可以通过让相机对拍摄的图像进行加密签名，从而拯救我们免受肆虐的 AI 伪造。为加密技术欢呼吧：https://www.aumasson.jp/murphy.html！","抱歉，这行不通。这里有很多情况需要考虑，所以我会尽量快地切入正题：","能够签名任意文件会破坏 C2PA 的信任模型：https://spec.c2pa.org/specifications/specifications/2.4/specs/C2PA_Specification.html#_trust_model。","Root 权限提升漏洞会破坏 Android 的密钥认证安全模型，Play Integrity 也是如此。","Android 设备可以通过低成本的硬件故障注入攻击被 Root：https://www.da.vidbuchanan.co.uk/blog/dram-emfi.html。","现有设备的硬件漏洞无法修补（这里有细微差别，稍后会讨论）。","因此，Android 平台上的 C2PA 是破碎的，无法现实地修补。","以上内容都不是“0day”，并且已在至少 90 天前报告给相关方（但任何头脑清楚的人都应该早有预见，正如许多人已经看到的那样）。","但等一下，还有更多！部分由于大语言模型（LLM）的原因，Root 权限提升漏洞的出现速度比 Google 推送补丁的速度还快。在撰写本文时，一击 Root 漏洞：https://github.com/alex193a/Root-My-Pixel 已经存在于完全打好补丁的 Google Pixel 设备上（通过 CVE-2026-43499：https://nvd.nist.gov/vuln/detail/CVE-2026-43499）。利用这些漏洞，任何人都可以在不需要硬件攻击的情况下生成 C2PA 伪造品。本文后面，我将提供操作指南。","如你所见，我在这里主要关注 Android。我会让 Google 来解释原因：https://blog.google/security/pixel-android-trusted-images-c2pa-content-credentials/:","Pixel Camera 应用程序实现了保证级别 2：https://github.com/c2pa-org/conformance-public/blob/main/conforming-products/conforming-products-list.json，由 C2PA 合规计划定义的最高安全等级：https://github.com/c2pa-org/conformance-public/blob/main/docs/current/C2PA%20Generator%20Product%20Security%20Requirements.pdf。目前，移动应用达到保证级别 2 仅可能在 Android 平台上实现。","也就是说，我正在攻击“最强”实现，仅仅是为了说明问题。这是一张 AI 生成的模糊图片，C2PA 说它是直接来自 Pixel Camera 应用的真实未经编辑的照片：（悬停以取消模糊，点击以“验证”）","：https://verify.contentauthenticity.org/?source=https%3A%2F%2Fretr0.id%2Fstuff%2Fnocors%2Fblog_frog.jpg","这是一个 Youtube 视频：https://www.youtube.com/watch?v=Uqpqw91pcac，信息框显示“用相机拍摄” （剧透：实际上并非如此）。","编辑，2026-08-25T19:12:16Z：Google 似乎已从视频描述中手动删除了“用相机拍摄”部分。不过这作用不大——继续阅读，了解如何给自己的媒体签名。我也换了一个 URL。伪造行为会继续，直到士气恢复。","顺便提一下，据传 Apple 正在：https://www.macrumors.com/2026/08/10/ios-27-apple-reference-image/ 开发自己的媒体来源解决方案，但目前尚不存在。当它出现时，我会告诉你我的看法。我怀疑他们的垂直整合会给他们带来显著优势，这可能会把最容易的攻击转向光学领域（拍摄屏幕等）。","无论如何，让我们深入了解细节。","证明仅对某些事项作出证明，包括：","安卓设备的“正常” ROOT 方式是解锁 bootloader 并刷入修改后的固件镜像，这个过程会强制设备执行出厂重置。认证会标记 bootloader 已解锁，Google 将拒绝向你的设备提供 C2PA 密钥（Netflix 不会提供高清内容，你的银行应用无法使用，等等）。","到目前为止，一切顺利（如果你喜欢这种玩法的话）。","然而，如果你通过利用漏洞获取设备的 root 权限，认证机制没有可靠的方式可以“察觉”。引导加载程序仍然是锁定的，AVB 密钥未被修改，设备仍然运行最初启动时的安全更新。现在，谷歌的服务器会愉快地向已被攻破的设备提供密钥。","认证机制设计背后的理论是，已知的软件本地特权提升（LPE）漏洞应当被修补，然后依赖方（验证认证报告的实体）可以要求用户安装更新，更新后的设备就不再容易受到 LPE 攻击。","CVE-2026-43499：https://nvd.nist.gov/vuln/detail/CVE-2026-43499 证明及时的补丁并不总是可用，但让我们给大家留个好处的怀疑，假装未修补漏洞的公开漏洞从不存在。还有两个剩余问题：","任何资金较充足的实体，从政府到移动取证公司，都可以建立私人漏洞库存（而且他们确实这样做）。这些正是你不希望伪造 C2PA 签名的群体。","低成本的硬件漏洞存在，无论补丁级别如何。","最初，我使用了硬件攻击。这是我早期研究的延续：你仅用打火机能获取 root 吗？：https://www.da.vidbuchanan.co.uk/blog/dram-emfi.html","我本打算在这里深入讨论，但坦率地说，纯软件漏洞：https://github.com/alex193a/Root-My-Pixel 途径：https://github.com/BuSung-dev/Root-My-Galaxy 抢了我的风头。软件漏洞存在时要方便得多，所以我会把完整的硬件细节留到以后再说。没有必要着急，因为硬件漏洞在大多数情况下是无法修补的。","如果你今天想复现我的发现，我推荐使用 Root My Pixel：https://github.com/alex193a/Root-My-Pixel 工具。（注意：虽然它今天支持大多数 Pixel 设备的最新八月安全更新，但你需要从 main 构建以启用该支持。我个人在 Pixel 8a 和 9a 上进行了测试。）","根基化后，剩下的攻击就是管道。我做了一个工具来实现这一点：keystork：https：//github.com/DavidBuchanan314/keystork。Keystork 采用客户端/服务器架构，允许客户端代码在 KeyStore API 下执行任意操作：https：//developer.android.com/reference/java/security/KeyStore，同时模拟任何已安装的应用。“服务器”（keystorkd）运行在已root的设备上，客户端是任何能使用我设计的有线协议的设备（默认通过Unix域套接字通过ADB转发传输）。参考客户端是一个带有相应CLI接口的Python库，但理论上Android应用可以与它通信，Shizuku：https：//github.com/rikkaapps/shizuku-style（不过你最好先构建一个授权/权限层）。","这里有一个针对Pixel Camera应用的“签名任意图片”PoC脚本：https://gist.github.com/DavidBuchanan314/fa0ffdaaaa31594e6a511118c1cea1e0:https://gist.github.com/DavidBuchanan314/fa0ffdaaaa31594e6a511118c1cea1e0","虽然软件漏洞利用可以且最终会被修补，但硬件漏洞利用是永无止境的。或者说，真的是这样吗？","理论上是，但实际上并不完全是。","我最初的策略（在PTE中切换位元）至今在Pixel设备上仍然有效。不过，它在三星设备上无法使用！","我最初在三星A07设备上做了一些测试（因为它们便宜）。漏洞当时有效，但安全更新后停止工作（我觉得时间点恰巧）。此次更新启用了三星的“RKP：https：//docs.samsungknox.com/admin/fundamentals/whitepaper/samsung-knox-mobile-security/system-security/real-time-kernel-protection/”缓解措施（实时内核保护，不要与远程密钥配置混淆......）","三星的缓解措施之一是使用EL2虚拟机监控程序对某些内存区域施加额外保护（有点像Microsoft的HVCI：https：//connormcgarr.github.io/hvci/）。我仍然可以用硬件漏洞来翻转PTE中的位，但即使我通过故障映射PTE到用户空间，EL2也不允许我覆盖它（这是我最初设计漏洞的关键部分）。","我有几个备用策略的计划，可以绕过三星的缓解措施，但我还没有实施它们。其中一个备用策略即使在存在硬件内存加密的情况下也应该有效。一旦我让它工作，我想把这个策略打包成一个“通用 Android 硬件 root”工具——敬请期待？（我也想攻击 HVCI 来玩反作弊，也可以关注这个。）","在硬件层面，存在几种解决方案将外部 DRAM 视为完全不可信，从而理论上缓解任何类型的总线故障攻击。示例包括 Intel MEE：https://eprint.iacr.org/2016/204.pdf，以及 Apple 的 SEP 内存保护引擎：https://support.apple.com/en-gb/guide/security/sec59b0b31ff/web#secb8d5e5708。然而，这些解决方案的性能不足以现实地运行整个 Android Linux 内核（这也是苹果只用它来保护 SEP 而不是主 AP，且英特尔在新版 SGX 中完全放弃该功能，导致了像 Battering RAM：https://batteringram.eu/ 这样的攻击）。","即使有最好的硬件级缓解措施，要在 Android 上修复 C2PA，也将涉及完全重构软件堆栈。整个图像处理管线，包括所有炫酷的 AI 功能，都需要在带有强大硬件内存保护的安全区域中运行。","我认为谷歌不会做这些，这可能就是他们以“不会修复（不可行）”的状态关闭我的报告的原因。进行所有这些重构是没有意义的，因为你仍然无法阻止“屏幕截图”类型的攻击。","顺便说一句，尽管是 WONTFIX 的结论，谷歌仍选择给我的提交奖励了 7500 美元的赏金：","感谢您提交报告。虽然硬件故障攻击和侧信道攻击不在我们的漏洞赏金计划范围内，但我们的安全团队认为您的发现很有价值，您提供的数据将帮助我们改进产品的未来版本。","我本不期望得到赏金（我知道从形式上讲不在范围内），所以这是一个惊喜。这将涵盖我在研究期间损坏的所有设备。但值得注意的是：","对我来说，最明显的 C2PA 攻击向量超出了 Google VRP 的范围。因此，VRP 并不能真正保护 Android 上的 C2PA 实现。","我这里一直关注的是 Pixel Camera 应用，但在 Android 上还有其他几个“C2PA Camera”应用。我调查过的所有这些应用都依赖于 Key Attestation 或 Play Integrity 来保障安全。它们都是以相同的方式存在漏洞，不过这些漏洞不仅限于 Google Pixel 设备。这意味着你不需要 root 一台 Pixel 设备，你可以选择整个 Android 生态系统中最便宜、最脆弱的设备来运行你的漏洞利用。","它们都是 Google 关于其平台安全有效性的误导性宣传的受害者。你可以在这里找到完整的“符合规范” C2PA 实现列表：https://github.com/c2pa-org/conformance-public/blob/main/conforming-products/conforming-products-list.json（所有在 attestationMethods 列表中包含 Android_KeyAttestation 或 Google_PlayIntegrity 的实现很可能存在漏洞）","在 C2PA 之外，我一直在使用我的硬件故障利用策略来 root 各种 Android 设备，包括 Amazon Fire TV stick 和 Meta Quest 3 VR 头显（我可能会在以后写更多关于此的内容！）","顺便说一下：Meta 已经在月初修补了 Quest 头显上的 CVE-2026-43499 本地提权漏洞，以阻止人们在 VR 视频游戏中作弊。我觉得完全不可思议的是，Google 甚至还没有为其旗舰 Pixel 设备发布修补程序。","虽然我最近才涉足 C2PA 生态系统，但 Hacker Factor 的 Neal Krawetz 博士（https://www.hackerfactor.com/blog/）多年来一直在发出警告。他的文章是我接触这一主题的起点，他在与我讨论问题以及协助漏洞披露协调方面都非常有帮助。","你可以在这里阅读他对这些漏洞的看法：https://www.hackerfactor.com/blog/index.php?/archives/1102-C2PA-and-Pixel-Glitter-Milk.html。","同时感谢来源和真实性标准评估工作组：https://cisa.umbc.edu/pasawg/（PASAWG），他们也在研究C2PA的有效性。","在准备我的 PoC 发布时，我有一个有趣的“如果……会怎样？”的想法。顺着这个思路，我发现了一个私钥泄露漏洞。我两天前向谷歌报告了这个问题，他们似乎在昨天已经修补了（这就是为什么我更喜欢硬件攻击，补丁会破坏乐趣）。我可能将来会写更多相关内容。","如果我不是胆小鬼，这里我本会贴出一份 Pixel Camera C2PA 私钥及相应的证书链。但我决定不这么做。如果你是想看一眼的记者，请告诉我。","我假设谷歌现在已经吊销了这把私钥（我在报告中已经包含了它）。然而，大多数 C2PA 验证工具并不检查撤销状态。我相信他们很快也会修复这个问题。","除非另有说明，所有由 Thinking Meat 创作的博客内容可在以下网址查看：https://web.mit.edu/people/dpolicar/writing/prose/text/thinkingMeat.html。","首页：/ - 博客索引：/blog/ - RSS：rss.xml","此博客是幽灵网站环的一部分：https://pixeldreams.tokyo/cgi-bin/webring.cgi","：https://pixeldreams.tokyo/cgi-bin/webring.cgi?after=https%3A%2F%2Fwww.da.vidbuchanan.co.uk%2Fblog%2F","来自我们非官方赞助商的一句话："]},"en":{"title":"C2PA cameras cannot withstand real-world tests: Android devices can be rooted to forge signatures","summary":"Security researcher David Buchanan pointed out that C2PA camera certification can be compromised on the Android platform. Through a root privilege escalation vulnerability (such as CVE-2026-43499), attackers can use StrongBox hardware signing to sign arbitrary data, forging C2PA-signed images and videos without the need for a hardware attack. This issue cannot be fixed through conventional patches and has been reported to the relevant parties 90 days in advance. 🔗 Read the original via AIHOT · https://aihot.virxact.com/items/cmta6v56y03ytroj25ggn7rlo","category":"Industry","source":"Hacker News 热门（buzzing.cc 中文翻译","aggregationSource":"Hacker News 热门（buzzing.cc 中文翻译","pageTitle":"C2PA cameras cannot withstand real-world tests: Android devices can be rooted to forge signatures - Aioga AI News","description":"Security researcher David Buchanan pointed out that C2PA camera certification can be compromised on the Android platform. Through a root privilege escalation vulnerability (such as...","url":"https://www.aioga.com/en/news/cmta6v56y03ytroj25ggn7rlo/","contentTranslated":true,"sourceHash":"70f5d0829c96a605","translatedAt":"2026-08-26T14:47:39.636Z"},"ja":{"title":"C2PAカメラは現実の試練に耐えられない：Android端はroot攻撃で署名を偽造可能","summary":"セキュリティ研究者のDavid Buchananは、C2PAカメラ認証がAndroidプラットフォームで突破される可能性があると指摘しています。root権限昇格の脆弱性（CVE-2026-43499など）を利用することで、攻撃者はStrongBoxハードウェア署名を使って任意のデータに署名し、C2PA署名済み画像や動画を偽造でき、ハードウェア攻撃は不要です。この問題は通常のパッチでは修正できず、関連者には90日前に報告済みです。 🔗 原文を読む via AIHOT · https://aihot.virxact.com/items/cmta6v56y03ytroj25ggn7rlo","category":"業界動向","source":"Hacker News 热门（buzzing.cc 中文翻译","aggregationSource":"Hacker News 热门（buzzing.cc 中文翻译","pageTitle":"C2PAカメラは現実の試練に耐えられない：Android端はroot攻撃で署名を偽造可能 - Aioga AIニュース","description":"セキュリティ研究者のDavid Buchananは、C2PAカメラ認証がAndroidプラットフォームで突破される可能性があると指摘しています。root権限昇格の脆弱性（CVE-2026-43499など）を利用することで、攻撃者はStrongBoxハードウェア署名を使って任意のデータに署名し、C2PA署名済み画像や動画を偽造でき、ハードウェア攻撃は不要です。...","url":"https://www.aioga.com/ja/news/cmta6v56y03ytroj25ggn7rlo/","contentTranslated":true,"sourceHash":"70f5d0829c96a605","translatedAt":"2026-08-26T14:47:56.301Z"},"ko":{"title":"C2PA 카메라는 현실의 시험을 견디지 못한다: Android에서는 루트 공격으로 서명을 위조할 수 있다","summary":"보안 연구원 David Buchanan은 C2PA 카메라 인증이 Android 플랫폼에서 공격당할 수 있다고 지적했습니다. root 권한 상승 취약점(예: CVE-2026-43499)을 통해 공격자는 StrongBox 하드웨어 서명을 이용해 임의의 데이터를 서명하고, 하드웨어 공격 없이 C2PA 서명 이미지와 비디오를 위조할 수 있습니다. 이 문제는 일반적인 패치로는 해결할 수 없으며, 관련 당사자에게 90일 전에 사전 보고되었습니다. 🔗 원문 읽기 via AIHOT · https://aihot.virxact.com/items/cmta6v56y03ytroj25ggn7rlo","category":"업계 동향","source":"Hacker News 热门（buzzing.cc 中文翻译","aggregationSource":"Hacker News 热门（buzzing.cc 中文翻译","pageTitle":"C2PA 카메라는 현실의 시험을 견디지 못한다: Android에서는 루트 공격으로 서명을 위조할 수 있다 - Aioga AI 뉴스","description":"보안 연구원 David Buchanan은 C2PA 카메라 인증이 Android 플랫폼에서 공격당할 수 있다고 지적했습니다. root 권한 상승 취약점(예: CVE-2026-43499)을 통해 공격자는 StrongBox 하드웨어 서명을 이용해 임의의 데이터를 서명하고, 하드웨어 공격 없이 C2PA 서명 이미지와 비디오를 위...","url":"https://www.aioga.com/ko/news/cmta6v56y03ytroj25ggn7rlo/","contentTranslated":true,"sourceHash":"70f5d0829c96a605","translatedAt":"2026-08-26T14:48:48.227Z"},"es":{"title":"Las cámaras C2PA no resisten la prueba de la realidad: en Android pueden ser atacadas con root para falsificar firmas","summary":"El investigador de seguridad David Buchanan señaló que la certificación de cámaras C2PA puede ser vulnerada en la plataforma Android. A través de vulnerabilidades de escalamiento de privilegios root (como CVE-2026-43499), los atacantes pueden utilizar la firma de hardware StrongBox para firmar datos arbitrarios, falsificar imágenes y videos con firma C2PA, sin necesidad de un ataque de hardware. Este problema no puede solucionarse mediante parches convencionales y fue reportado a las partes correspondientes con 90 días de anticipación. 🔗 Leer el artículo original vía AIHOT · https://aihot.virxact.com/items/cmta6v56y03ytroj25ggn7rlo","category":"Industria","source":"Hacker News 热门（buzzing.cc 中文翻译","aggregationSource":"Hacker News 热门（buzzing.cc 中文翻译","pageTitle":"Las cámaras C2PA no resisten la prueba de la realidad: en Android pueden ser atacadas con root para falsificar firmas - Aioga Noticias de IA","description":"El investigador de seguridad David Buchanan señaló que la certificación de cámaras C2PA puede ser vulnerada en la plataforma Android. A través de vulnerabilidades de escalamiento d...","url":"https://www.aioga.com/es/news/cmta6v56y03ytroj25ggn7rlo/","contentTranslated":true,"sourceHash":"70f5d0829c96a605","translatedAt":"2026-08-26T14:48:48.372Z"},"fr":{"title":"Les appareils photo C2PA ne résistent pas à l'épreuve de la réalité : sur Android, ils peuvent être attaqués par root pour falsifier les signatures","summary":"Le chercheur en sécurité David Buchanan a indiqué que la certification C2PA des appareils photo peut être contournée sur la plateforme Android. Grâce à une vulnérabilité d'élévation de privilèges root (comme CVE-2026-43499), un attaquant peut utiliser la signature matérielle StrongBox sur n'importe quelles données, falsifier des images et vidéos avec signature C2PA, sans nécessiter d'attaque matérielle. Ce problème ne peut pas être corrigé par un patch classique et a été signalé aux parties concernées 90 jours à l'avance. 🔗 Lire l'article original via AIHOT · https://aihot.virxact.com/items/cmta6v56y03ytroj25ggn7rlo","category":"Industrie","source":"Hacker News 热门（buzzing.cc 中文翻译","aggregationSource":"Hacker News 热门（buzzing.cc 中文翻译","pageTitle":"Les appareils photo C2PA ne résistent pas à l'épreuve de la réalité : sur Android, ils peuvent être attaqués par root pour falsifier les signatures - Aioga Actualités IA","description":"Le chercheur en sécurité David Buchanan a indiqué que la certification C2PA des appareils photo peut être contournée sur la plateforme Android. Grâce à une vulnérabilité d'élévatio...","url":"https://www.aioga.com/fr/news/cmta6v56y03ytroj25ggn7rlo/","contentTranslated":true,"sourceHash":"70f5d0829c96a605","translatedAt":"2026-08-26T14:49:44.048Z"},"de":{"title":"C2PA-Kameras halten der Realität nicht stand: Auf Android-Seite können Root-Angriffe Signaturen fälschen","summary":"Der Sicherheitsforscher David Buchanan weist darauf hin, dass die C2PA-Kameraauthentifizierung auf der Android-Plattform umgangen werden kann. Durch einen Root-Rechteskalationsfehler (wie CVE-2026-43499) kann ein Angreifer beliebige Daten mit der StrongBox-Hardware-Signatur nutzen und gefälschte C2PA-signierte Bilder und Videos erstellen, ohne einen Hardwareangriff durchführen zu müssen. Das Problem kann nicht mit herkömmlichen Patches behoben werden und wurde den Betroffenen bereits 90 Tage im Voraus gemeldet. 🔗 Originalartikel lesen via AIHOT · https://aihot.virxact.com/items/cmta6v56y03ytroj25ggn7rlo","category":"行业动态","source":"Hacker News 热门（buzzing.cc 中文翻译","aggregationSource":"Hacker News 热门（buzzing.cc 中文翻译","pageTitle":"C2PA-Kameras halten der Realität nicht stand: Auf Android-Seite können Root-Angriffe Signaturen fälschen - Aioga KI-News","description":"Der Sicherheitsforscher David Buchanan weist darauf hin, dass die C2PA-Kameraauthentifizierung auf der Android-Plattform umgangen werden kann. Durch einen Root-Rechteskalationsfehl...","url":"https://www.aioga.com/de/news/cmta6v56y03ytroj25ggn7rlo/","contentTranslated":true,"sourceHash":"70f5d0829c96a605","translatedAt":"2026-08-26T14:49:46.029Z"},"pt-BR":{"title":"Câmeras C2PA não resistem ao teste da realidade: no Android podem ser atacadas por root para falsificar assinaturas","summary":"O pesquisador de segurança David Buchanan apontou que a autenticação de câmeras C2PA no Android pode ser comprometida. Através de uma vulnerabilidade de escalonamento de privilégios root (como CVE-2026-43499), um atacante pode usar a assinatura de hardware StrongBox para qualquer dado, forjando imagens e vídeos com assinatura C2PA, sem necessidade de ataque ao hardware. Esse problema não pode ser corrigido por patches comuns e já foi relatado aos envolvidos com 90 dias de antecedência. 🔗 Leia o artigo completo via AIHOT · https://aihot.virxact.com/items/cmta6v56y03ytroj25ggn7rlo","category":"行业动态","source":"Hacker News 热门（buzzing.cc 中文翻译","aggregationSource":"Hacker News 热门（buzzing.cc 中文翻译","pageTitle":"Câmeras C2PA não resistem ao teste da realidade: no Android podem ser atacadas por root para falsificar assinaturas - Aioga Notícias de IA","description":"O pesquisador de segurança David Buchanan apontou que a autenticação de câmeras C2PA no Android pode ser comprometida. Através de uma vulnerabilidade de escalonamento de privilégio...","url":"https://www.aioga.com/pt-BR/news/cmta6v56y03ytroj25ggn7rlo/","contentTranslated":true,"sourceHash":"70f5d0829c96a605","translatedAt":"2026-08-26T14:50:41.208Z"},"ru":{"title":"Камера C2PA не выдерживает проверку реальностью: на Android её можно атаковать через root, чтобы подделать подпись","summary":"Исследователь безопасности Дэвид Бьюкенен указал, что C2PA аутентификация камеры на платформе Android может быть взломана. Через уязвимость повышения привилегий root (например, CVE-2026-43499) злоумышленники могут использовать аппаратную подпись StrongBox для любых данных, подделывать изображения и видео с C2PA-подписью без необходимости аппаратной атаки. Эту проблему невозможно исправить обычным патчем, о ней за 90 дней было заранее сообщено соответствующим сторонам. 🔗 Читать оригинал via AIHOT · https://aihot.virxact.com/items/cmta6v56y03ytroj25ggn7rlo","category":"行业动态","source":"Hacker News 热门（buzzing.cc 中文翻译","aggregationSource":"Hacker News 热门（buzzing.cc 中文翻译","pageTitle":"Камера C2PA не выдерживает проверку реальностью: на Android её можно атаковать через root, чтобы подделать подпись - Aioga Новости ИИ","description":"Исследователь безопасности Дэвид Бьюкенен указал, что C2PA аутентификация камеры на платформе Android может быть взломана. Через уязвимость повышения привилегий root (например, CVE...","url":"https://www.aioga.com/ru/news/cmta6v56y03ytroj25ggn7rlo/","contentTranslated":true,"sourceHash":"70f5d0829c96a605","translatedAt":"2026-08-26T14:50:40.165Z"},"ar":{"title":"كاميرات C2PA لا تتحمل اختبار الواقع: يمكن لجهاز أندرويد أن يتعرض لهجوم الرووت لتزوير التوقيع","summary":"أشار الباحث الأمني ديفيد بوكانان إلى أن مصادقة كاميرات C2PA يمكن اختراقها على منصة أندرويد. من خلال ثغرة رفع صلاحيات الروت (مثل CVE-2026-43499)، يمكن للمهاجم استخدام توقيع الأجهزة StrongBox لأي بيانات، وتزوير صور وفيديوهات بتوقيع C2PA دون الحاجة لهجوم مادي على الأجهزة. لا يمكن إصلاح هذه المشكلة عبر التحديثات العادية، وقد تم الإبلاغ عنها للأطراف المعنية قبل 90 يومًا. 🔗 اقرأ المقال الأصلي عبر AIHOT · https://aihot.virxact.com/items/cmta6v56y03ytroj25ggn7rlo","category":"行业动态","source":"Hacker News 热门（buzzing.cc 中文翻译","aggregationSource":"Hacker News 热门（buzzing.cc 中文翻译","pageTitle":"كاميرات C2PA لا تتحمل اختبار الواقع: يمكن لجهاز أندرويد أن يتعرض لهجوم الرووت لتزوير التوقيع - Aioga أخبار الذكاء الاصطناعي","description":"أشار الباحث الأمني ديفيد بوكانان إلى أن مصادقة كاميرات C2PA يمكن اختراقها على منصة أندرويد. من خلال ثغرة رفع صلاحيات الروت (مثل CVE-2026-43499)، يمكن للمهاجم استخدام توقيع الأجهزة...","url":"https://www.aioga.com/ar/news/cmta6v56y03ytroj25ggn7rlo/","contentTranslated":true,"sourceHash":"70f5d0829c96a605","translatedAt":"2026-08-26T14:51:41.683Z"},"hi":{"title":"C2PA कैमरा वास्तविक परीक्षण का सामना नहीं कर सकता: एंड्रॉइड डिवाइस को रूट करके साइन से संबंधित हमले किए जा सकते हैं","summary":"सुरक्षा शोधकर्ता डेविड बुचानन ने बताया कि C2PA कैमरा प्रमाणीकरण एंड्रॉइड प्लेटफ़ॉर्म पर तोड़ा जा सकता है। रूट अनुमतियों के उन्नयन की खामियों (जैसे CVE-2026-43499) के माध्यम से, हमलावर StrongBox हार्डवेयर साइनिंग का उपयोग करके किसी भी डेटा पर हस्ताक्षर कर सकते हैं, C2PA साइन किए हुए चित्र और वीडियो बना सकते हैं, और इसके लिए हार्डवेयर हमला आवश्यक नहीं है। इस समस्या को सामान्य पैच के माध्यम से ठीक नहीं किया जा सकता, और संबंधित पक्षों को 90 दिन पहले ही रिपोर्ट कर दिया गया है। 🔗 मूल लेख पढ़ें via AIHOT · https://aihot.virxact.com/items/cmta6v56y03ytroj25ggn7rlo","category":"行业动态","source":"Hacker News 热门（buzzing.cc 中文翻译","aggregationSource":"Hacker News 热门（buzzing.cc 中文翻译","pageTitle":"C2PA कैमरा वास्तविक परीक्षण का सामना नहीं कर सकता: एंड्रॉइड डिवाइस को रूट करके साइन से संबंधित हमले किए जा सकते हैं - Aioga AI समाचार","description":"सुरक्षा शोधकर्ता डेविड बुचानन ने बताया कि C2PA कैमरा प्रमाणीकरण एंड्रॉइड प्लेटफ़ॉर्म पर तोड़ा जा सकता है। रूट अनुमतियों के उन्नयन की खामियों (जैसे CVE-2026-43499) के माध्यम से, हमल...","url":"https://www.aioga.com/hi/news/cmta6v56y03ytroj25ggn7rlo/","contentTranslated":true,"sourceHash":"70f5d0829c96a605","translatedAt":"2026-08-26T14:51:39.110Z"},"it":{"title":"Le fotocamere C2PA non resistono alla prova della realtà: su Android possono essere attaccate da root per falsificare le firme","summary":"Il ricercatore di sicurezza David Buchanan ha indicato che la certificazione C2PA per le fotocamere può essere compromessa sulla piattaforma Android. Attraverso vulnerabilità di escalation dei privilegi root (come CVE-2026-43499), un aggressore può utilizzare la firma hardware di StrongBox su dati arbitrari, falsificando immagini e video firmati C2PA senza la necessità di un attacco hardware. Questo problema non può essere risolto con patch convenzionali ed è stato segnalato alle parti interessate con 90 giorni di anticipo. 🔗 Leggi l'articolo originale via AIHOT · https://aihot.virxact.com/items/cmta6v56y03ytroj25ggn7rlo","category":"行业动态","source":"Hacker News 热门（buzzing.cc 中文翻译","aggregationSource":"Hacker News 热门（buzzing.cc 中文翻译","pageTitle":"Le fotocamere C2PA non resistono alla prova della realtà: su Android possono essere attaccate da root per falsificare le firme - Aioga Notizie IA","description":"Il ricercatore di sicurezza David Buchanan ha indicato che la certificazione C2PA per le fotocamere può essere compromessa sulla piattaforma Android. Attraverso vulnerabilità di es...","url":"https://www.aioga.com/it/news/cmta6v56y03ytroj25ggn7rlo/","contentTranslated":true,"sourceHash":"70f5d0829c96a605","translatedAt":"2026-08-26T14:52:39.854Z"},"nl":{"title":"C2PA-camera kan de realiteitstest niet doorstaan: Android-kant kan door root-aanvallen valse handtekeningen maken","summary":"Veiligheidsonderzoeker David Buchanan wees erop dat C2PA-camera-authenticatie op het Android-platform kan worden gekraakt. Via een root-privilege-escalatie kwetsbaarheid (zoals CVE-2026-43499) kan een aanvaller willekeurige data ondertekenen met de StrongBox-hardwarehandtekening, C2PA-handtekeningbeelden en -video's vervalsen, zonder hardware-aanval. Dit probleem kan niet worden opgelost met reguliere patches en is 90 dagen van tevoren gemeld aan de betrokken partijen. 🔗 Lees het originele artikel via AIHOT · https://aihot.virxact.com/items/cmta6v56y03ytroj25ggn7rlo","category":"行业动态","source":"Hacker News 热门（buzzing.cc 中文翻译","aggregationSource":"Hacker News 热门（buzzing.cc 中文翻译","pageTitle":"C2PA-camera kan de realiteitstest niet doorstaan: Android-kant kan door root-aanvallen valse handtekeningen maken - Aioga AI-nieuws","description":"Veiligheidsonderzoeker David Buchanan wees erop dat C2PA-camera-authenticatie op het Android-platform kan worden gekraakt. Via een root-privilege-escalatie kwetsbaarheid (zoals CVE...","url":"https://www.aioga.com/nl/news/cmta6v56y03ytroj25ggn7rlo/","contentTranslated":true,"sourceHash":"70f5d0829c96a605","translatedAt":"2026-08-26T14:52:37.583Z"},"tr":{"title":"C2PA kamerası gerçek testlere dayanamaz: Android tarafı root saldırısıyla imza taklit edilebilir","summary":"Güvenlik araştırmacısı David Buchanan, C2PA kamera doğrulamasının Android platformunda aşılabileceğini belirtti. Root yetkisi yükseltme açığı (ör. CVE-2026-43499) aracılığıyla, saldırgan StrongBox donanım imzasını kullanarak herhangi bir veriyi imzalayabilir, C2PA imzalı resim ve videoları sahteleyebilir ve bunun için donanım saldırısına gerek duymaz. Bu sorun normal yamalarla giderilemez ve ilgili taraflara 90 gün önceden bildirildi. 🔗 Orijinal makaleyi okuyun via AIHOT · https://aihot.virxact.com/items/cmta6v56y03ytroj25ggn7rlo","category":"行业动态","source":"Hacker News 热门（buzzing.cc 中文翻译","aggregationSource":"Hacker News 热门（buzzing.cc 中文翻译","pageTitle":"C2PA kamerası gerçek testlere dayanamaz: Android tarafı root saldırısıyla imza taklit edilebilir - Aioga AI Haberleri","description":"Güvenlik araştırmacısı David Buchanan, C2PA kamera doğrulamasının Android platformunda aşılabileceğini belirtti. Root yetkisi yükseltme açığı (ör. CVE-2026-43499) aracılığıyla, sal...","url":"https://www.aioga.com/tr/news/cmta6v56y03ytroj25ggn7rlo/","contentTranslated":true,"sourceHash":"70f5d0829c96a605","translatedAt":"2026-08-26T14:53:38.396Z"},"vi":{"title":"Máy ảnh C2PA không chịu nổi thử thách thực tế: Phiên bản Android có thể bị tấn công root để giả mạo chữ ký","summary":"Nhà nghiên cứu bảo mật David Buchanan chỉ ra rằng chứng thực camera C2PA có thể bị tấn công trên nền tảng Android. Thông qua lỗ hổng nâng quyền root (như CVE-2026-43499), kẻ tấn công có thể sử dụng chữ ký phần cứng StrongBox để ký bất kỳ dữ liệu nào, giả mạo ảnh và video có chữ ký C2PA mà không cần tấn công phần cứng. Vấn đề này không thể được sửa bằng bản vá thông thường, đã được báo cáo cho các bên liên quan trước 90 ngày. 🔗 Đọc nguyên văn via AIHOT · https://aihot.virxact.com/items/cmta6v56y03ytroj25ggn7rlo","category":"行业动态","source":"Hacker News 热门（buzzing.cc 中文翻译","aggregationSource":"Hacker News 热门（buzzing.cc 中文翻译","pageTitle":"Máy ảnh C2PA không chịu nổi thử thách thực tế: Phiên bản Android có thể bị tấn công root để giả mạo chữ ký - Tin tức AI Aioga","description":"Nhà nghiên cứu bảo mật David Buchanan chỉ ra rằng chứng thực camera C2PA có thể bị tấn công trên nền tảng Android. Thông qua lỗ hổng nâng quyền root (như CVE-2026-43499), kẻ tấn cô...","url":"https://www.aioga.com/vi/news/cmta6v56y03ytroj25ggn7rlo/","contentTranslated":true,"sourceHash":"70f5d0829c96a605","translatedAt":"2026-08-26T14:53:44.722Z"},"id":{"title":"Kamera C2PA tidak tahan uji kenyataan: di sisi Android dapat diserang root untuk memalsukan tanda tangan","summary":"Peneliti keamanan David Buchanan menunjukkan bahwa otentikasi kamera C2PA dapat ditembus pada platform Android. Melalui kerentanan peningkatan hak akses root (seperti CVE-2026-43499), penyerang dapat menggunakan tanda tangan perangkat keras StrongBox untuk data apa pun, memalsukan gambar dan video dengan tanda tangan C2PA, tanpa perlu serangan perangkat keras. Masalah ini tidak dapat diperbaiki melalui patch biasa, dan telah dilaporkan kepada pihak terkait 90 hari sebelumnya. 🔗 Baca artikel asli via AIHOT · https://aihot.virxact.com/items/cmta6v56y03ytroj25ggn7rlo","category":"行业动态","source":"Hacker News 热门（buzzing.cc 中文翻译","aggregationSource":"Hacker News 热门（buzzing.cc 中文翻译","pageTitle":"Kamera C2PA tidak tahan uji kenyataan: di sisi Android dapat diserang root untuk memalsukan tanda tangan - Berita AI Aioga","description":"Peneliti keamanan David Buchanan menunjukkan bahwa otentikasi kamera C2PA dapat ditembus pada platform Android. Melalui kerentanan peningkatan hak akses root (seperti CVE-2026-4349...","url":"https://www.aioga.com/id/news/cmta6v56y03ytroj25ggn7rlo/","contentTranslated":true,"sourceHash":"70f5d0829c96a605","translatedAt":"2026-08-26T14:54:37.159Z"},"th":{"title":"กล้อง C2PA ไม่ทนต่อการทดสอบในชีวิตจริง: ฝั่ง Android สามารถถูกโจมตีด้วย root เพื่อปลอมแปลงลายเซ็น","summary":"นักวิจัยด้านความปลอดภัย David Buchanan ชี้ว่า การยืนยันกล้อง C2PA สามารถถูกโจมตีได้บนแพลตฟอร์ม Android โดยผ่านช่องโหว่ยกระดับสิทธิ์ root (เช่น CVE-2026-43499) ผู้โจมตีสามารถใช้ StrongBox ในการเซ็นข้อมูลใด ๆ ก็ได้ ปลอมแปลงภาพและวิดีโอที่มีลายเซ็น C2PA โดยไม่ต้องโจมตีฮาร์ดแวร์ ปัญหานี้ไม่สามารถแก้ไขด้วยแพตช์ปกติ และได้รายงานไปยังฝ่ายที่เกี่ยวข้องล่วงหน้า 90 วัน 🔗 อ่านต้นฉบับ via AIHOT · https://aihot.virxact.com/items/cmta6v56y03ytroj25ggn7rlo","category":"行业动态","source":"Hacker News 热门（buzzing.cc 中文翻译","aggregationSource":"Hacker News 热门（buzzing.cc 中文翻译","pageTitle":"กล้อง C2PA ไม่ทนต่อการทดสอบในชีวิตจริง: ฝั่ง Android สามารถถูกโจมตีด้วย root เพื่อปลอมแปลงลายเซ็น - ข่าว AI Aioga","description":"นักวิจัยด้านความปลอดภัย David Buchanan ชี้ว่า การยืนยันกล้อง C2PA สามารถถูกโจมตีได้บนแพลตฟอร์ม Android โดยผ่านช่องโหว่ยกระดับสิทธิ์ root (เช่น CVE-2026-43499) ผู้โจมตีสามารถใช้ Str...","url":"https://www.aioga.com/th/news/cmta6v56y03ytroj25ggn7rlo/","contentTranslated":true,"sourceHash":"70f5d0829c96a605","translatedAt":"2026-08-26T14:54:47.591Z"},"pl":{"title":"Aparat C2PA nie wytrzymuje próby rzeczywistości: na Androidzie można go zrootować i sfałszować podpis","summary":"Badacz ds. bezpieczeństwa David Buchanan wskazał, że uwierzytelnianie aparatów C2PA na platformie Android może zostać złamane. Poprzez lukę eskalacji uprawnień root (taką jak CVE-2026-43499), atakujący może korzystać z podpisu sprzętowego StrongBox dla dowolnych danych, fałszując obrazy i filmy z podpisem C2PA, bez potrzeby ataku na sprzęt. Problem ten nie może zostać naprawiony za pomocą standardowej poprawki i został zgłoszony odpowiednim stronom z wyprzedzeniem 90 dni. 🔗 Przeczytaj oryginał via AIHOT · https://aihot.virxact.com/items/cmta6v56y03ytroj25ggn7rlo","category":"行业动态","source":"Hacker News 热门（buzzing.cc 中文翻译","aggregationSource":"Hacker News 热门（buzzing.cc 中文翻译","pageTitle":"Aparat C2PA nie wytrzymuje próby rzeczywistości: na Androidzie można go zrootować i sfałszować podpis - Aioga Wiadomości AI","description":"Badacz ds. bezpieczeństwa David Buchanan wskazał, że uwierzytelnianie aparatów C2PA na platformie Android może zostać złamane. Poprzez lukę eskalacji uprawnień root (taką jak CVE-2...","url":"https://www.aioga.com/pl/news/cmta6v56y03ytroj25ggn7rlo/","contentTranslated":true,"sourceHash":"70f5d0829c96a605","translatedAt":"2026-08-26T14:55:49.398Z"}},"evidenceTier":"verified-news","reviewStatus":"editorial-selected","indexable":true,"editorialCover":""}}