{
  "id": 3305726,
  "title": "C2PA Cameras Do Not Survive Contact With Reality",
  "url": "https://urgent.news/2026/08/25/c2pa-cameras-do-not-survive-contact-with-reality",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-08-25T15:51:24.000Z",
  "source": {
    "name": "Lobsters",
    "slug": "lobsters",
    "url": "https://www.da.vidbuchanan.co.uk/blog/android-c2pa.html"
  },
  "original_language": "en",
  "account": "C2PA, a technology designed to prevent AI forgeries by having cameras cryptographically sign images, is flawed on Android platforms. Several factors contribute to this, including reliance on Key Attestation and Google Play Integrity, which both fail when apps are rooted. Android devices can be rooted through low-cost hardware fault injection attacks, and existing hardware vulnerabilities cannot be patched. This renders C2PA ineffective on Android, as anyone can now generate forged images without hardware attacks. Google's Pixel Camera app achieved the highest security rating within the C2PA Conformance Program, but this is due to software-only exploits being more convenient and easily available. The existing hardware exploits cannot be patched and pose a significant threat, especially to groups with advanced resources. Additionally, hardware exploits cannot be patched, leaving Android devices vulnerable. Users can now sign any image with C2PA, as demonstrated by provided PoC scripts and tools, such as keystork, which allows arbitrary operations against the KeyStore API.",
  "summary": null,
  "key_points": [],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}