SECURITY·중요도 8·2026. 08. 26.·GeekNews
C2PA 카메라는 현실의 공격 앞에서 무너짐
── KO ──────────────────
C2PA 카메라 앱의 보안 취약점이 드러났다.
Android의 C2PA 카메라 앱은 Key Attestation과 Google Play Integrity로 보안을 강화했지만, 루트 권한을 얻은 공격자는 여전히 정상적인 C2PA 서명을 생성할 수 있는 취약점이 발견됐다. 부트로더가 잠겨 있고 최신 보안 업데이트가 적용되어도 권한 상승 취약점을 통해 루팅이 가능하다는 점이 지적되었다.
── EN ──────────────────
Vulnerabilities in the C2PA camera app expose security risks.
The C2PA camera app for Android employs Key Attestation and Google Play Integrity to prevent tampering. However, attackers with root access can generate valid C2PA signatures for arbitrary files, revealing significant vulnerabilities. Even with a locked bootloader and the latest security updates, privilege escalation flaws allow for rooting the device.