Tech & AI News
Hacker News

C2PA Cameras Do Not Survive Contact with Reality

C2PA camera apps on Android depend on Key Attestation and Google Play Integrity to prevent signing of arbitrary files, but root privilege-escalation exploits—available via low-cost hardware fault injection and one-click exploits like CVE-2026-43499—bypass these protections, rendering the Android implementation unpatchable. Consequently, attackers can forge C2PA-signed media on fully-patched Pixel devices, undermining the trust model despite the platform achieving the highest Assurance Level 2.