iOS has per-image access permissions, #GrapheneOS has storage scopes. Please use these features. You shouldn't be saving copies of your seed phrase like this too.
Derek Ross's avatar Derek Ross
Malware has been found in both Google Play and Apple's App Store that uses optical character recognition to steal cryptocurrency wallet recovery phrases from users' photo galleries. That's...kind of cool and an interesting attack vector. Don't take screenshots or photos of your wallet's recovery phrases. https://m.slashdot.org/story/438433
View quoted note →

Replies (3)

Arándano's avatar
Arándano 10 months ago
But it is not clear to me which app is.. Is the Play Store with gallery access privileges? Or is it a malware app installed by the user?
It's the malware app. Typical Android malware like this asks for invasive permissions to then abuse them. Play Services doesn't provide apps permissions on their behalf.
Android 14+ also has per-image access permissions and now no new updates can be made to apps that requests full access to all images like in the past.