If you run the web extension of WhatsApp, you should make sure you’re running version 0.1.4481 or higher to ensure that you’re safe. Here’s the reason why via Help Net Security:
Check Point security researcher Kasif Dekel found that to exploit the vulnerability, an attacker simply needs to send a WhatsApp user a seemingly innocent vCard contact card, containing malicious code. Once opened in WhatsApp Web, the executable file in the contact card can run, further compromising computers by distributing malware including ransomware, bots, remote access tools (RATs), and other types of malicious code.
To target an individual, all an attacker needs is the phone number associated with the account. WhatsApp Web allows users to view any type of media or attachment that can be sent or viewed by the mobile platform/application, including images, videos, audio files, locations and contact cards.
This doesn’t sound good. I’d be taking immediate steps to update to the latest version if I were you. What’s really scary is the scope of this problem. It could in theory encompass 200 million users. That’s not a trivial number of users.
Related
This entry was posted on September 8, 2015 at 1:28 pm and is filed under Commentary with tags Security, WhatsApp. You can follow any responses to this entry through the RSS 2.0 feed.
You can leave a response, or trackback from your own site.
Millions Of WhatsApp Web Users Vulnerable To Hacking
If you run the web extension of WhatsApp, you should make sure you’re running version 0.1.4481 or higher to ensure that you’re safe. Here’s the reason why via Help Net Security:
Check Point security researcher Kasif Dekel found that to exploit the vulnerability, an attacker simply needs to send a WhatsApp user a seemingly innocent vCard contact card, containing malicious code. Once opened in WhatsApp Web, the executable file in the contact card can run, further compromising computers by distributing malware including ransomware, bots, remote access tools (RATs), and other types of malicious code.
To target an individual, all an attacker needs is the phone number associated with the account. WhatsApp Web allows users to view any type of media or attachment that can be sent or viewed by the mobile platform/application, including images, videos, audio files, locations and contact cards.
This doesn’t sound good. I’d be taking immediate steps to update to the latest version if I were you. What’s really scary is the scope of this problem. It could in theory encompass 200 million users. That’s not a trivial number of users.
Share this:
Like this:
Related
This entry was posted on September 8, 2015 at 1:28 pm and is filed under Commentary with tags Security, WhatsApp. You can follow any responses to this entry through the RSS 2.0 feed. You can leave a response, or trackback from your own site.