steven36 Posted December 17, 2019 Share Posted December 17, 2019 The issue has been patched, so remember to update your apps. WhatsApp may be one of the most popular messaging apps, but it has had its share of security issues. Security research group Check Point Research today announced the existence of another one, having recently uncovered a defect through which a single malicious user could crash the apps of all members of a group chat. After joining a group chat, a user could edit specific message parameters using the WhatsApp web interface and a browser debugging tool. Then they could create an "unstoppable crash-loop for all group chat members" which could only be fixed by uninstalling and reinstalling the app. The exploit would prevent members from returning to the group and and also lose all history of the chat. This follows another WhatsApp vulnerability discovered by Check Point last year. The FakesApp vulnerability, as it is known, allowed people to manipulate messages in group chats to make it appear as if other users had said things they had not. This worked by manipulating the parameters used by the WhatsApp web interface to fake the apparent sender of a message. After finding the latest defect, Check Point disclosed the problem to WhatsApp in August as part of a bug bounty program. WhatsApp patched the issue in September with version 2.19.58, so take this as a reminder to keep your apps up to date. Source Link to comment Share on other sites More sharing options...
Recommended Posts
Archived
This topic is now archived and is closed to further replies.