WhatsApp vulnerability enabled attackers to gain files and message access on Android devices

SHARE:

WhatsApp has been grappling with its fair share of bugs and issues and a new flaw has now come to light. Before we share any details, we urg...

WhatsApp has been grappling with its fair share of bugs and issues and a new flaw has now come to light. Before we share any details, we urge you update the app on your Android devices, since the vulnerability we are going to talk about could enable hackers gain access to your files and messages on the app. As per a security researcher with the pseudonym Awakened, a double-free vulnerability in the popular messaging app could crash a device or even enable hackers gain access to your smartphone. First reported by TNW, the bug affects devices running on Android 8 and above, which means iOS users don’t need to worry about this particular bug. 

Before you panic, do note that Facebook was notified of the flaw and the company patched the issue with WhatsApp version 2.19.244. The researcher notes, in a Github blog post, that using just a malicious GIF file, one could trigger a Remote Control Execution (RCE) exploit. This could potentially enable an attacker to proceed in two ways; they could perform local privilege escalation and install a malicious app that can be used to steal files in WhatsApp sandbox, including message database. 

Remote code execution was also possible by exploiting the flaw, which would make use of WhatsApp‘s Gallery view. In an update, WhatsApp told TNW that there’s no reason to believe the flaw affected any users. “The key point that the [vulnerability disclosure] makes is that this issue affects the user on the sender side, meaning the issue could in theory occur when the user takes action to send a GIF. The issue would impact their own device.” as per a statement provided by WhatsApp’s spokesperson to TNW. “It was reported and quickly addressed last month. We have no reason to believe this affected any users though of course we are always working to provide the latest security features to our users.”

 



from Latest Technology News https://ift.tt/2InpF2x

COMMENTS

Name

7,1,Airtel,1,Andriod,1,Android,4,Android Q,1,apex,1,Apple,7,Apps,1,Asus Rog,1,Black Shark 2,2,Boeing 737 MAX,1,Bsnl,2,camera,2,CPU,3,Donald Trump,1,Earphone,1,Facebook,5,Fan,1,Fitbit,1,foldable Phone,2,Fortnite,1,Galaxy A40,1,Galaxy s10,1,Galaxy s10e,1,Games,10,gaming,1,Google,6,Google Pixel 2,1,Honor 10i,1,Huawe,1,Huawei,6,Huawei GT,1,IBM,1,Instagram,2,Internet,2,ios,2,iPad,2,iphone,2,Israel,1,jiomart,1,Laptop,1,Leica Q2,1,M20,1,mac,1,MacOS,1,Mi 9,1,Mi A2,1,Mi LED TV,1,MicroSoft,3,mobile,1,Moon,2,Mozilla,1,Nasa,2,News,1,Nokia,4,Nokia 62,1,Nvidias,1,OnePlus,4,Oppo,5,P30,3,Pixel,1,Poco F1,1,Pubg,12,Qualcomm,2,Redmi 3,1,Redmi 6 Pro,1,Redmi 7,1,Redmi Note 7,1,reliance,1,Reno,1,samsung,11,Skype,1,SmartPhone,56,Social,5,Spotify,1,Tech,35,Telecom,3,Touchpad,1,Tournament,1,TV,1,Twitter,1,Vivo,2,Watch,2,WhatsApp,1,Xbox,1,Xiaomi,16,y9li,1,
ltr
item
Genius Baba: WhatsApp vulnerability enabled attackers to gain files and message access on Android devices
WhatsApp vulnerability enabled attackers to gain files and message access on Android devices
http://feeds.feedburner.com/~r/digit/latest-news/~4/qDvxm83APgI
Genius Baba
https://geniusbabaa.blogspot.com/2019/10/whatsapp-vulnerability-enabled.html
https://geniusbabaa.blogspot.com/
https://geniusbabaa.blogspot.com/
https://geniusbabaa.blogspot.com/2019/10/whatsapp-vulnerability-enabled.html
true
7104319406113350277
UTF-8
Loaded All Posts Not found any posts VIEW ALL Readmore Reply Cancel reply Delete By Home PAGES POSTS View All RECOMMENDED FOR YOU LABEL ARCHIVE SEARCH ALL POSTS Not found any post match with your request Back Home Sunday Monday Tuesday Wednesday Thursday Friday Saturday Sun Mon Tue Wed Thu Fri Sat January February March April May June July August September October November December Jan Feb Mar Apr May Jun Jul Aug Sep Oct Nov Dec just now 1 minute ago $$1$$ minutes ago 1 hour ago $$1$$ hours ago Yesterday $$1$$ days ago $$1$$ weeks ago more than 5 weeks ago Followers Follow THIS PREMIUM CONTENT IS LOCKED STEP 1: Share. STEP 2: Click the link you shared to unlock Copy All Code Select All Code All codes were copied to your clipboard Can not copy the codes / texts, please press [CTRL]+[C] (or CMD+C with Mac) to copy