Close X
Monday, December 2, 2024
ADVT 
International

Warning: Malicious Flaw Affects 1 Billion WhatsApp Users

Darpan News Desk IANS, 04 Oct, 2019 09:02 PM

    WhatsApp is by far one of the most secure messaging platforms in the world; however, like every technology out there, it does come with its own set of unique flaws.


    This year itself, various reports have disclosed certain vulnerabilities that have plagued WhatsApp which can be exploited by attacks or which have the potential to leave users open to harmful consequences. The flaws range from sophisticated nation-state attacks to misleading functionality as well as targeted hacking.


    Recently, a new bug has come to light that allows an attacker to use a malicious GIF image file to open a vulnerability in WhatsApp and potentially access user content. As per a report by Forbes, this bug was identified and shared by “technologist and information security enthusiast” Awakened on Github. Also, there is a detailed explanation of how this bug works.


    It’s a bit complex but basically, the bug depends on an attacker pushing the malicious GIF file to the victim’s device through any channel. This could include WhatsApp, email or any messaging platform.


    With this GIF on the device, when a victim opens the gallery within WhatsApp to send any image (not necessarily a malicious image), the hack gets activated and the device and its contents become potentially vulnerable.


    WhatsApp needs to step up its game in five areas.


    Wakened has warned, “WhatsApp users please do update to latest WhatsApp version (2.19.244 or above) to stay safe from this bug.”


    The report states, “From a technical perspective, the attack relies on a so-called double-free bug, where the same memory address on the device is called twice, pushing memory allocation into an unexpected spin, which either crashes the app or opens the vulnerability.


    Replicating an attack using the bug does not seem to be entirely reliable, and affects different versions of the operating system software in different ways, but a bug is a bug and once identified can be developed and expanded upon.”


    Speaking to TNW regarding this bug, WhatsApp states there have been no reports of any attacks on users exploiting this vulnerability. What’s more “this issue affects the user on the sender side, meaning the issue could, in theory, occur when the user takes action to send a GIF. The issue would impact their own device.”


    To this Awakened says, “I would say that the above claim is not correct. The spokesperson must have misunderstood the issue.”


    What Awakened is trying to say is that although there is some trigger that’s required from the victim’s side, opening the gallery within WhatsApp is a regular task and nothing that would raise suspicion. So, as long as the attacker has planted the image on the device, the vulnerability can be exploited.


    WhatsApp states that the bug “was reported and quickly addressed last month. We have no reason to believe this affected any users though of course, we are always working to provide the latest security features to our users.”


    The report by Forbes goes on to state, “The bug has been identified and patched—the specifics of how it’s exploited matter less now than ensuring that users update to the latest version of the app.


    And while this only seems to impact Android devices, that advice to update is universal. Once a vulnerability reaches the public domain, there is always a risk of it being used—would-be attackers are well aware of the inertia that sees many users update apps much more sporadically than is healthy for their data security.”

    MORE International ARTICLES

    Khalsa Aid’s Ravi Singh Apologises On Behalf Of The Sikh Community For 'Sikhs For Trump'

    Ravi Singh of Khalsa Aid is apologising on the behalf of the Sikh community after photos of men in Sikhs for Trump community cropped up online. 

    Khalsa Aid’s Ravi Singh Apologises On Behalf Of The Sikh Community For 'Sikhs For Trump'

    Aid To Pak To Stay 'Suspended', Says US Report Ahead Of Imran Khan Visit

    At the direction of US President Donald Trump, the United States had suspended all its security assistance to Pakistan in January 2018. This is first high-level visit by a Pakistani prime minster to the White House during the Trump administration.  

    Aid To Pak To Stay 'Suspended', Says US Report Ahead Of Imran Khan Visit

    Runaway Indian Boy Mohammed Pervez In Sharjah Returns Home

    A 15-year-old Indian boy, who sneaked out of his home in Sharjah over two weeks ago after apparently being scolded by his mother, returned home to his family here on Friday.

    Runaway Indian Boy Mohammed Pervez In Sharjah Returns Home

    Nobody Will Say ‘India Murdabad’ Anymore, Says Gopal Singh Chawla After Removal From Kartarpur Panel

    While addressing a gathering of Sikh devotees at the historical place, he showed anger towards Pakistan government, saying that despite all sacrifices made by him, he was booted out from the panel.

    Nobody Will Say ‘India Murdabad’ Anymore, Says Gopal Singh Chawla After Removal From Kartarpur Panel

    ‘Minorities Are Fed Up Of Indian Government’: Rapper Hard Kaur Supports ‘Khalistan’ Campaign Powered By Banned Sikhs For Justice

    In a number of videos posted on social media four days ago, Kaur is seen supporting the referendum and appealing people not to be “fooled” by those who oppose Khalistan.

    ‘Minorities Are Fed Up Of Indian Government’: Rapper Hard Kaur Supports ‘Khalistan’ Campaign Powered By Banned Sikhs For Justice

    ‘Where Is That Exactly?’: Donald Trump’s Shocker When Rohingya Refugee Seeks US Help

    Donald Trump was having an interaction with a group of survivors of religious persecution, which included Nobel laureate Nadia Murad as well, in the Oval Office on the sidelines of a major meeting at the State Department on Wednesday.   

    ‘Where Is That Exactly?’: Donald Trump’s Shocker When Rohingya Refugee Seeks US Help