Another WhatsApp Vulnerability Has Been Found

November 21, 2019

Written by wukovits

another whatsapp vulnerability has been foundWhatsApp is the most popular messaging platform in the world.

Unfortunately, that means it’s got a giant bullseye on it where hackers are concerned.

In recent months, the company has faced no end of troubles as a raft of vulnerabilities have been exposed and exploited by hackers from every corner of the globe.

The company is still reeling from the blowback associated with these various issues, but their troubles don’t seem to be over yet.  Just last month, WhatsApp quietly found and patched another vulnerability.  This one is tracked as CVE-2019-11931. It is a stack-based buffer overflow issue relating to the way that older WhatsApp versions parsed MP4 metadata, allowing attackers to launch denial-of-service or remote code execution attacks.

All a hacker needed in order to exploit the flaw was a target’s phone number and a specially crafted MP4 file. It just had to be constructed in such a way that it installed a backdoor upon opening.  From there, a wide range of malware could be installed at the hackers’ leisure.  Worse, this vulnerability was found in both the consumer and Enterprise versions of WhatsApp for all major platforms, including Windows, iOS, and Android.

An advisory bulletin was recently published by WhatsApp’s parent company, Facebook. See the list of versions they provided below.

The list of affected versions are as follows:

  • Business for iOS versions prior to 2.19.100
  • Business for Android versions prior to 2.19.104
  • Windows Phone versions prior to and including 3.18.368
  • Enterprise Client versions prior to 2.25.3
  • iOS versions prior to 2.19.100
  • Android versions prior to 2.19.274

If there’s a silver lining here, it is that the company has confirmed that there have been no instances of this exploit having been used ‘in the wild’ and the company has already issued a patch.  If you’re one of WhatsApp’s legions of users, check to be sure you’re running the latest version. If not, update immediately to be on the safe side.

Used with permission from Article Aggregator

Bayou Tech

We provide solutions for your business. Find out how we can help.

Related Articles

Key Considerations for Effective Cybersecurity Implementation

Consider this: In the realm of cybersecurity, things often get tangled in the web of "you should do it anyway" arguments. Yet, for busy business owners bombarded with daily "must-dos," deciphering the essentials from the fluff can feel like a cyber maze. We aim to...

New Graphene Technology May Increase Hard Drive Storage

HDDs are old, well understood technology. They haven't changed much in recent years. In fact, increasingly, people are writing them off, preferring SSDs for their greater speed and smaller size, even though HDDs are less expensive. The clever folks at the University...