financetom
Business
financetom
/
Business
/
New WhatsApp bug may steal files, messages with GIFs
News World Market Environment Technology Personal Finance Politics Retail Business Economy Cryptocurrency Forex Stocks Market Commodities
New WhatsApp bug may steal files, messages with GIFs
Oct 3, 2019 5:45 AM

A security bug has been found in Facebook-owned instant messenger WhatsApp that could let attackers to obtain access to a device and steal data by sending a malicious GIF file.

The danger stems from a double-free bug in WhatsApp, according to a researcher going by the nickname Awakened, The Next Web reported on Wednesday.

A double-free vulnerability is a memory corruption anomaly that could crash an application or open up an exploit vector that attackers can abuse to gain access to users' device.

According to Awakened's post on GitHub, the flaw resided in WhatsApp's Gallery view implementation that is used to generate previews for photographs, videos and GIFs.

All it takes to perform the attack is to craft a malicious GIF, and wait for the user to open the WhatsApp gallery, the report added.

"The exploit works well until WhatsApp version 2.19.230. The vulnerability is officially patched in WhatsApp version 2.19.244," wrote the researcher.

The bug also works for Android 8.1 and Android 9.0 OS but does not work for Android 8.0 and below.

In the older Android versions, double-free could still be triggered. However, because of the malloc calls by the system after the double-free, the app just crashes before reaching to the point that we could control the PC register, according to a report in Gizmodo.

First Published:Oct 3, 2019 2:45 PM IST

Comments
Welcome to financetom comments! Please keep conversations courteous and on-topic. To fosterproductive and respectful conversations, you may see comments from our Community Managers.
Sign up to post
Sort by
Show More Comments
Related Articles >
Commerzbank on Overnight News
Commerzbank on Overnight News
May 26, 2025
06:21 AM EDT, 05/07/2025 (MT Newswires) -- Commerzbanm in its European Sunrise note of Wednesday highlighted: Markets: Long-end United States Treasuries rally into New York close amid high demand at 10-year auction. Front-end weaker in Asia while 30-year remains better bid. E-minis and Asian stocks edge higher. EUR trades around $1.135. Brent increases above $62.5/barrel. U.S.: Treasury Secretary Scott Bessent...
Owens Corning's Q1 Adjusted Earnings Fall, Net Sales Rise
Owens Corning's Q1 Adjusted Earnings Fall, Net Sales Rise
May 26, 2025
06:20 AM EDT, 05/07/2025 (MT Newswires) -- Owens Corning ( OC ) reported Q1 adjusted earnings from continuing operations Wednesday of $2.97 per diluted share, down from $3.40 a year earlier. Analysts polled by FactSet expected $2.87. Net sales for the quarter ended March 31 was $2.53 billion, up from $2.02 billion a year earlier. Analysts' revenue estimate was not...
Volvo Cars to cut 5% of jobs at South Carolina plant as tariffs bite
Volvo Cars to cut 5% of jobs at South Carolina plant as tariffs bite
May 26, 2025
STOCKHOLM (Reuters) -Volvo Cars said on Wednesday it would make production changes and cut 5% of the workforce at its Charleston plant in the United States due to changing market conditions and evolving trade policies, including tariffs. A spokesperson for Volvo Cars said the changes would affect about 125 of the 2,500 employees at its factory in South Carolina.  It...
Google agrees $36 million fine for anti-competitive deals with Australia telcos
Google agrees $36 million fine for anti-competitive deals with Australia telcos
Aug 17, 2025
SYDNEY, Aug 18 (Reuters) - Google agreed on Monday to pay a A$55 million ($35.8 million) fine in Australia after the consumer watchdog found it had hurt competition by paying the country's two largest telcos to pre-install its search application on Android phones, excluding rival search engines. The fine extends a bumpy period for the Alphabet-owned internet giant in Australia,...
Copyright 2023-2026 - www.financetom.com All Rights Reserved