Hacker News
David Buchanan Extracted C2PA Signing Keys From Pixel Camera and Signed an AI Frog as a Real Photo
In an August 25 post, Buchanan defeated C2PA content credentials on Pixel 8a and 9a devices running Google's Camera app, the configuration holding C2PA's highest Assurance Level 2 rating. He used two routes: DRAM electromagnetic fault injection to flip bits in page table entries, and for the public demo the CVE-2026-43499 one-click root on fully patched devices. With root, the StrongBox secure enclave will sign arbitrary data, so he produced an AI-generated image and a YouTube video both verifying as camera-captured, and notes most C2PA verifiers do not check revocation anyway.
↳ Follow the thread