The C2PA feature, designed to ensure photo authenticity and prevent tampering, has been anticipated as a cornerstone of a trustworthy visual media era.
However, reports from creator forums have revealed that the C2PA feature implemented in the has a vulnerability that allows 'authenticity' to be faked. Nikon is currently investigating, and this issue is not just a rumor but a real security concern.
The Blind Spot of 'Multiple Exposure' Threatening Authenticity
The core of this vulnerability lies in the 'multiple exposure' feature of the . While originally intended for creative expression, this feature allows users to overlay non-C2PA-compliant images or AI-generated images, enabling them to be authenticated as 'genuine photos' with C2PA signatures.

Photo by A-Photo(エース フォト)
Although the cryptographic technology itself has not been breached, the vulnerability exploits weaknesses in the implementation.
Countermeasures Underway: Awareness Among Creators is Key
has already begun investigations and is considering fixes in future firmware updates. Possible measures include preventing the use of non-C2PA-signed images as materials for multiple exposure or disabling signatures within this feature altogether.

Photo by gaku
Until then, it is advisable to avoid placing absolute trust in C2PA-signed images generated by the .

