Dangerous ‘acropalypse’ bug in Windows Snipping Tool fixed in emergency security update — install it now

How to screen record on Windows 11 illustrated with a picture of the Snipping Tool on the Windows 11 desktop
(Image credit: Tom's Guide)

Microsoft has released an emergency security update for both Windows 10 and Windows 11 which addresses a dangerous bug in its Snipping Tool utility.

The bug has been dubbed ‘acropalypse’ (tracked as CVE-2023-2803) and occurs when image editors like the search giant’s Snipping Tool doesn’t properly remove cropped image data when overwriting the original file according to BleepingComputer.

After testing a fix for the bug in its Windows Insider Canary channel, Microsoft has now publicly released a fix for both the Snip & Sketch app in Windows 10 and the Snipping Tool program in Windows 11. The company is urging Windows users to apply the update now to patch the acropalypse vulnerability.

Once installed, Windows 11 Snipping Tool will be version 11.2302.20.0 while Windows 10 Snip & Sketch will be version 10.2008.3001.0. 

What is the acropalypse flaw and how does it work?

Two screenshots illustrating the Pixel aCropalypse flaw. The first, taken from a Google Pixel 6, is a heavily cropped image of an app, showing only the bottom quarter of the image. On the right is the image restored using the aCropalypse.app tool, which has rebuilt almost the entire page save for a partly corrupted/blacked-out section at the top.

(Image credit: Tom's Guide)

Although it is now affecting Windows PCs, the acropalypse flaw was first found on Pixel Phones inside Google’s Pixel Markup tool

Discovered by security researchers David Buchanan and Simon Aarons, the acropalypse flaw causes an image’s original data to be retained even after it has been edited or cropped. The danger here is that if a user shares a picture of something sensitive like their credit card with its number redacted via image cropping, it may be possible to partially recover the original photo.

To show how the acropalypse bug could be exploited by an attacker, Buchanan and Aarons created an online screenshot recovery tool that tries to recover edited images created on a Google Pixel phone like the Pixel 7 or Pixel 7 Pro.

The impact of the acropalypse bug is quite large, with security researchers telling BleepingComputer that more than 4,000 images hosted on VirusTotal are affected. However, on image hosting websites, the number of images affected by the bug is likely even higher.

How to protect your Windows PC from this dangerous flaw

Laptop showing security lock on screen

(Image credit: Shutterstock)

Now that Microsoft has rolled out an emergency security update to patch this issue, it’s up to you to install it.

To do so, you first need to open the Microsoft Store and go to Library and then to Get Updates. Clicking on the button will install the latest version of the Windows Snipping Tool or Snip & Sketch automatically on your PC.

After patching the acropalypse flaw, you might want to take some time to further secure your PC from the latest threats. Besides updating Windows Defender and ensuring it’s enabled on your computer, you may also want to install one of the best antivirus software programs for additional protection.

When it comes to keeping your photos and other images safe, you can use the best cloud storage to keep an extra copy of them in the cloud or even one of the best cloud backup services to automate this process.

Even though the acropalypse flaw is considered dangerous, Microsoft has classified the vulnerability as “Low” severity due to the fact that it "requires uncommon user interaction and several factors outside of an attacker's control” to exploit. Still, keeping your PC updated is one of the best ways to protect your devices and your data from hackers.

More from Tom's Guide

TOPICS
Anthony Spadafora
Managing Editor Security and Home Office

Anthony Spadafora is the managing editor for security and home office furniture at Tom’s Guide where he covers everything from data breaches to password managers and the best way to cover your whole home or business with Wi-Fi. He also reviews standing desks, office chairs and other home office accessories with a penchant for building desk setups. Before joining the team, Anthony wrote for ITProPortal while living in Korea and later for TechRadar Pro after moving back to the US. Based in Houston, Texas, when he’s not writing Anthony can be found tinkering with PCs and game consoles, managing cables and upgrading his smart home. 

Read more
Windows
240 million Windows 10 users are vulnerable to six different hacker exploits — protect yourself now
MacBook Pro 16-inch 2021 sitting on a patio table
Critical macOS flaw puts your data and cameras at risk — update right now
How to disable the Windows key
Microsoft patches over 160 security flaws including 3 active zero days — update your PC right now
laptop anger
Latest Windows 11 update reportedly breaking major parts of the operating system
A laptop on a windowsill in the middle of a Windows update
Microsoft is ending support for Windows 10 soon — 5 ways to make sure your PC is secure
iPhone 16 Pro shown held in hand
Apple just patched its first zero-day flaw of the year — update your iPhone and Mac right now
Latest in Online Security
A magnifying glass on top of the Steam logo in a web browser
Valve just pulled a malicious game demo spreading info-stealing malware from Steam
MacBook Pro 2023
New Mac attack is tricking users into thinking their computer is locked — how to stay safe
Hacker using a stolen social security card
Your Social Security number is a literal gold mine for scammers and identity thieves — here’s how to keep it safe
An open lock depicting a data breach
Half a million teachers hit in major data breach with SSNs, financial data and more exposed — what to do now
Green skull on smartphone screen.
Malicious Android apps with 60 million installs bombarding phones with ads and phishing attacks — how to stay safe
Malware
Dangerous new password-stealing trojan automatically reinstalls itself on infected PCs
Latest in News
Rendered images of rumored foldable iPhone.
Foldable iPhone report just revealed key details — here's what we know
NYTimes Connections
NYT Connections today hints and answers — Saturday, March 23 (#651)
NYT Strands on a cellphone
NYT Strands today — hints, spangram and answers for game #385 (Sunday, March 23 2025)
Nintendo Switch 2
Nintendo Switch 2 rumored specs — here’s what we know so far
iPhone 17 Pro render
iPhone 17 Pro — 7 biggest rumored upgrades
CAD renderings of the Google Pixel 10 Pro XL
Pixel 10 leak could be good news for all Android phones