The past few months have not been good to WhatsApp users. Unfortunately, that doesn't look like it's about to change any time soon.
The Facebook-owned messaging app acknowledged and patched a major vulnerability that gave hackers the ability to access files on a victim's computer. All you had to do to fall prey to this attack was click a disguised link preview sent via the messaging app. In other words, it would have been an easy mistake for users to make.
Importantly, this did not affect every single WhatsApp user. Rather, a WhatsApp user had to have the iOS version of the messaging app paired to either a PC or MacOS WhatsApp desktop app.
"A vulnerability in WhatsApp Desktop when paired with WhatsApp for iPhone allows cross-site scripting and local file reading," reads the Facebook bug report. "Exploiting the vulnerability requires the victim to click a link preview from a specially crafted text message."
In a Feb. 4 blog post, the security researcher who discovered and disclosed the vulnerability detailed his process and noted that WhatsApp should really get its shit together.
"It is 2020," wrote Gal Weizman, "no product should be allowing a full read from the file system and potentially a [remote code execution] from a single message."
Patrick Wardle, a security researcher at Jamf and founder of Objective-See, told Mashable over Twitter direct message that "often desktop versions of apps aren't as well audited or well written ...and thus often open to attacks."
He added that this specific specific bug "was likely rather trivial to exploit," but cautioned against people freaking out.
"[Still]," wrote Wardle, "a super neat bug, and had the potential to impact lots of users (I use WhatsApp desktop), so definitely happy a security researcher uncovered it and that FB patched it quickly."
We reached out to Facebook in an effort to determine how many people were vulnerable to this exploit and how many, if any, were actually affectedby it. We've received no response as of press time.
Notably, WhatsApp vulnerabilities can have serious consequences. Just this past month, a security firm hired by Amazon CEO Jeff Bezos claimed in a report that the CEO's phone may have been hacked following the receipt of a malicious WhatsApp message. And while Bezos will be fine, people with less power and resources who fall victim to similar attacks may not fare as well.
Facebook is aware of this, but suggests at least some of the blame should lie elsewhere. Following the news of Bezos' hacked phone, the company's vice president of Europe, the Middle East and Africa, Nicola Mendelsohn, suggested to Bloombergthat Apple is the real problem here.
"One of the things that it highlights is actually some of the potential underlying vulnerabilities that exist on the actual operating systems on phones," Mendelsohn told the publication. "From a WhatsApp perspective, from a Facebook perspective, the thing that we care about the most, the thing that we invest in is making sure that the information that people have with us is safe and secure."
SEE ALSO: Mic on Bezos' hacked phone possibly compromised for months
Which, yeah, great. Making sure WhatsApp information is "safe and secure" sounds great, but perhaps that should include not allowing malicious texts that let hackers access victims' computers? Sounds like a good place to start.
Or, if that's too much, maybe Facebook should start recommending Signal.
UPDATE: Feb. 5, 2020, 2:02 p.m. PST:This story has been updated with comment from Patrick Wardle.
Copyright © 2023 Powered by
WhatsApp bug let hackers access computers with an iOS app and a text-寸地尺天网
sitemap
文章
4348
浏览
81
获赞
7534
Tumblr loses nearly 30 percent of its page views after banning porn
Tumblr has suffered a massive drop in traffic since banning porn late last year.In November 2018, TuBattlefield V DLSS Tested: Overpromised, Underdelivered
Nvidia's deep learning super sampling, or DLSS, is one of the highly anticipated features present onThe Science of Keeping It Cool
Almost every single piece of modern electronics generates heat whether we notice it or not. WithoutThe State of Nvidia RTX Ray Tracing: One Year Later
Time to revisit the state of ray tracing. It's been months since we last discussed ray tracing in deAOC calls out Kushner: ‘What's next, putting nuclear codes in Instagram DMs?’
It's a cold day in government hell when Instagram DMs get a shoutout at a House Oversight CommitteeResident Evil 3 Benchmarked
Resident Evil 3 is a remake of the PlayStation original released back in 1999. The game follows Jill5 Days of Awesome Wallpapers: Cars and Sports Wallpapers
A great wallpaper can start your day off on a good mood. There’s certainly no shortage of places toHow CPUs are Designed and Built
We all think of the CPU as the "brains" of a computer, but what does that actually mean? What is goiComedian gives her family brilliant informational pamphlets before going on a date
Anticipating her family's inevitable questions, Mary Beth Barone prepared an informational pamphletRyzen 5 3600 vs. 3600X: Which should you buy?
We were among the first publications to review the Ryzen 5 3600 and at $200 we found the 6-core, 12-10+ Tools for Finding and Deleting Duplicate Files on Windows
We've covered many ways that you can save space on your storage drives over the years, most recentlyNvidia DLSS in 2020: Stunning Results
We've been waiting to reexamine Nvidia's Deep Learning Super Sampling for a long time, partly becausArtists on Twitter are drawing their favorite shipping dynamics for this new meme
Once you've binge-watched enough Netflixshows, you start to see a pattern in the characters you getTesting AMD's new Radeon Anti
Alongside the release of AMD's new Radeon RX 5700 Navi GPUs, the company rolled out two new features2016's $170 GPU vs. 2019's $170 GPUs
Today we're going to review the sub-$200 graphics card market and see how it compares to what we wer