Categories: News

WhatsApp new flaw helps hackers in breaching data

A researcher has discovered a flaw in WhatsApp which is allowing hackers to breach the privacy of users and steal their data. The researcher, named “Awakend”, found a double-free bug in the app.

In a double-free bug a file, which is named “free() free()”, will cause memory corruption that can crash applications and make way for hackers by opening a path to steal data. In this case, all the hacker needs to do is modify a GIF to make it malicious, send it to users and wait for them to open the WhatsApp gallery.

The bug is allowing hackers to steal data including messages, video, audio, and other files with the help of a malicious GIF image file. In the month of May, Facebook issued a warning of an attacker. Facebook thought the attacker is a private company working for a government which is taking advantage of a security flaw on WhatsApp to snooping on human right organizations.

Awakend wrote a write up and published that on GitHub, in the article he explains that the issue sits in the view application of WhatsApp gallery. He wrote,

“The exploit works well for Android 8.1 and 9.0, but does not work for Android 8.0 and below, in the older Android versions, double-free could still be triggered. However, the app just crashes before reaching the point that we could control the PC register. Facebook acknowledged and patched it officially in WhatsApp version 2.19.244. WhatsApp users, please do update to the latest WhatsApp version (2.19.244 or above) to get rid of this bug.”

WhatsApp, while talking to The Next Web, said “that there were no reports of any attacks on users exploiting this vulnerability,” and that “this issue affects the user on the sender side, meaning the issue could in theory occur when the user takes action to send a GIF. The issue would impact their own device.”

This is not the first time hackers have attacked whatsapp, few months ago a malware attacked the whatsapp user and started replaces popular apps with fake ones and tricks the users, serving them advertisements according to cybersecurity researchers.

Sponsored
AbuBakar

Share
Published by
AbuBakar

Recent Posts

Rumors Indicate iPhone 17 May Feature Unconventional Camera Design

Apple is reportedly preparing for a significant design overhaul with its iPhone 17 series, blending…

4 hours ago

First AI-Powered Teacher Launched in Pakistan’s Private School

Karachi: A private school in Karachi has unveiled Pakistan’s first AI-powered teacher, a groundbreaking move…

5 hours ago

Yahoo Surprises Users with Its Latest Android Launcher

Third-party apps have long been a staple of the Android ecosystem, but their appeal has…

6 hours ago

Phase-II Review of PTCL-Telenor Deal Finalized by CCP

ISLAMABAD: The Competition Commission of Pakistan (CCP) has completed its Phase-II review of Pakistan Telecommunication…

6 hours ago

Xiaomi’s SU7 Achieves New Production Record, Driving Q3 Growth

Xiaomi has shattered records by producing 100,000 vehicles in just 230 days. This is nearly…

8 hours ago

Teachers Can Now Access OpenAI’s Free AI Course

OpenAI, in collaboration with nonprofit organization Common Sense Media, announced on Wednesday the launch of…

9 hours ago