C2PA Cameras Do Not Survive Contact With Reality

David Buchanan demonstrates that C2PA's content authenticity system on Android is fundamentally broken. By combining known root exploits and low-cost hardware fault injection, he forges C2PA-signed images and videos that pass verification as genuine camera captures. He explains how Key Attestation and Play Integrity fail against these attacks, and why hardware vulnerabilities can't be patched. Google acknowledged the issue but marked it as 'Won't fix (infeasible)', awarding a $7,500 bounty. The article includes a proof-of-concept tool and highlights that all C2PA camera apps on Android are similarly vulnerable.
C2PA on the Android platform is broken, in a way that cannot be realistically patched.