Windows 11 Snipping Tool can leak vulnerable information you cropped out

Windows 11 Snipping Tool screen recording
(Image credit: Microsoft)

Update: March 23, 2023 at 2:08 PM ET

Microsoft appears to be testing a fix for the Snipping Tool bug. A tweet by Twitter user Xeno suggests that the solution may only be available for Canary Insiders at this time, though that is not confirmed.

What you need to know

  • The Windows 11 Snipping Tool has a vulnerability that can share data and details that have been cropped out of screenshots.
  • Information that has been cropped out of images can be at least partially restored.
  • The vulnerability is similar to what has been discovered with the screenshot tool in Google Pixel phones, which has been called "aCropalypse."

Windows 11's Snipping Tool has a vulnerability that can be exploited to expose data that users have cropped out of screenshots. The problem is similar to "aCropalypse," which is a vulnerability with the screenshot tool on Google Pixel phones. In both instances, a person can at least partially recover data that has been cropped out of images.

The exact workings of the vulnerabilities differ slightly, but the end result is the same. Chris Blume, a retired software engineer noted the Windows 11 Snipping Tool flaw:

David Buchanan took a closer look at the phenomenon and shared insights on Twitter.

The security implications of this vulnerability are severe. If someone used the Snipping Tool to capture a page that included their address, credit card number, or other personal information, they would likely assume cropping the image would remove that data. Any shared images containing that information could open the doors to identity theft or other issues.

Security expert Will Dorman confirmed the vulnerability and shared the steps to confirm the problem:

BleepingComputer shared a technical breakdown of how the vulnerability can be exploited and to what extent data can be restored through it.

There's already an aCropalypse screenshot recovery app that can restore information from Pixel phones. While that does not work with images from the Windows 11 Snipping Tool at this time, a similar app could arrive in the future. Buchannan shared a Python script with BleepingComputer that is able to recover files from Windows 11.

Microsoft confirmed to BleepingComputer that it is aware of reports and looking into the issue. "We are aware of these reports and are investigating. We will take action as needed to help keep customers protected," said a Microsoft spokesperson.

Sean Endicott
News Writer and apps editor

Sean Endicott is a tech journalist at Windows Central, specializing in Windows, Microsoft software, AI, and PCs. He's covered major launches, from Windows 10 and 11 to the rise of AI tools like ChatGPT. Sean's journey began with the Lumia 740, leading to strong ties with app developers. Outside writing, he coaches American football, utilizing Microsoft services to manage his team. He studied broadcast journalism at Nottingham Trent University and is active on X @SeanEndicott_ and Threads @sean_endicott_.