financetom
Business
financetom
/
Business
/
New WhatsApp bug may steal files, messages with GIFs
News World Market Environment Technology Personal Finance Politics Retail Business Economy Cryptocurrency Forex Stocks Market Commodities
New WhatsApp bug may steal files, messages with GIFs
Oct 3, 2019 5:45 AM

A security bug has been found in Facebook-owned instant messenger WhatsApp that could let attackers to obtain access to a device and steal data by sending a malicious GIF file.

The danger stems from a double-free bug in WhatsApp, according to a researcher going by the nickname Awakened, The Next Web reported on Wednesday.

A double-free vulnerability is a memory corruption anomaly that could crash an application or open up an exploit vector that attackers can abuse to gain access to users' device.

According to Awakened's post on GitHub, the flaw resided in WhatsApp's Gallery view implementation that is used to generate previews for photographs, videos and GIFs.

All it takes to perform the attack is to craft a malicious GIF, and wait for the user to open the WhatsApp gallery, the report added.

"The exploit works well until WhatsApp version 2.19.230. The vulnerability is officially patched in WhatsApp version 2.19.244," wrote the researcher.

The bug also works for Android 8.1 and Android 9.0 OS but does not work for Android 8.0 and below.

In the older Android versions, double-free could still be triggered. However, because of the malloc calls by the system after the double-free, the app just crashes before reaching to the point that we could control the PC register, according to a report in Gizmodo.

First Published:Oct 3, 2019 2:45 PM IST

Comments
Welcome to financetom comments! Please keep conversations courteous and on-topic. To fosterproductive and respectful conversations, you may see comments from our Community Managers.
Sign up to post
Sort by
Show More Comments
Related Articles >
Lazard reports August outflows of $7.5 bln due to client's strategy switch, source says
Lazard reports August outflows of $7.5 bln due to client's strategy switch, source says
Sep 13, 2024
Sept 12 (Reuters) - Lazard's ( LAZ ) asset management business saw net outflows of $7.5 billion in August after one of its clients switched to a passive investing strategy, a person familiar with the matter told Reuters on Thursday. The bank was one of several asset managers to be impacted after the client restructured its developed market assets portfolio,...
AST SpaceMobile Reports Orbital Launch of First Five Commercial Satellites
AST SpaceMobile Reports Orbital Launch of First Five Commercial Satellites
Sep 13, 2024
10:46 AM EDT, 09/12/2024 (MT Newswires) -- AST SpaceMobile ( ASTS ) said Thursday it has launched the first five of its BlueBird commercial satellites into low Earth orbit from Cape Canaveral, Florida. The BlueBird satellites are planned to offer non-continuous cellular broadband service across the US and in select markets globally, the company said. Shares of of the company...
Lazard reports August outflows of $7.5 billion due to client's strategy switch, source says
Lazard reports August outflows of $7.5 billion due to client's strategy switch, source says
Sep 13, 2024
(Reuters) - Lazard's ( LAZ ) asset management business saw net outflows of $7.5 billion in August after one of its clients switched to a passive investing strategy, a person familiar with the matter told Reuters on Thursday. The bank was one of several asset managers to be impacted after the client restructured its developed market assets portfolio, the person...
Plug Power Wins Green Methanol Technical Evaluation Contract in Portugal
Plug Power Wins Green Methanol Technical Evaluation Contract in Portugal
Sep 13, 2024
10:53 AM EDT, 09/12/2024 (MT Newswires) -- Plug Power ( PLUG ) said Thursday it was awarded a contract to provide technical evaluation phase support for the green methanol project of Dourogas and CapWatt in Portugal. Plug Power ( PLUG ) said it will provide detailed information on its proton exchange membrane electrolyzer technology during the front end engineering design...
Copyright 2023-2026 - www.financetom.com All Rights Reserved