Sunday, 06 October 2019 05:44

Why you need to update your WhatsApp right NOW

Rate this item
(0 votes)

You better update WhatsApp right now. A researcher has discovered a nasty vulnerability in the Facebook-owned privacy-oriented messenger that made it possible to for attackers to gain access to your files and messages ⁠— by sending you a malicious GIF.

The danger stems from a double-free bug in WhatsApp, according to a researcher going by the nickname Awakened. For those unfamiliar with the term, a double-free vulnerability refers to a memory corruption anomaly that could crash an app, or worse ⁠— open up an exploit vector that attackers can abuse to obtain access to your device. All it takes to perform the attack is to craft a malicious GIF, and trick a user into loading it.

In a technical write-up on GitHub, the researcher explains the flaw resided in WhatsApp‘s Gallery view implementation, which is used to generate previews for images, videos, and GIFs.

The exploit seems to affect primarily Android devices. “The exploit works well for Android 8.1 and 9.0, but does not work for Android 8.0 and below,” Awakened writes. “In the older Android versions, double-free could still be triggered. However, […] the app just crashes before reaching to the point that we could control the PC register.”

The researcher has already notified Facebook of this shortcoming, and the company has since fixed the issue. To protect yourself against the exploit, you should download the latest version of the app.

“Facebook acknowledged and patched it officially in WhatsApp version 2.19.244. WhatsApp users, please do update to latest WhatsApp version (2.19.244 or above) to get rid of this bug,” the researcher urged users in his blog post.

Not a first for WhatsApp

This is hardly the first time WhatsApp has dealt with potentially harmful flaws in its software.

Earlier this year, the Financial Times reported a vulnerability in the messaging app allowed attackers to slip in spyware on users’ devices. WhatsApp rushed to fix the issue, but did not clarify how many users were affected by this loophole.

More recently, researchers found a kink in WhatsApp that made it possible to manipulate or spoof messages.

It remains unclear if attackers were able to exploit the double-free vulnerability in the wild, but we’ve reached out to Facebook for a clarification, and will update this piece accordingly if we hear back.

 

Compiled by Olalekan Adeleye

The Next Web

January 06, 2025

Marketers request N100bn loan to prevent mass closure of fuel outlets

The Petroleum Products Retail Outlet Owners Association of Nigeria (PETROAN) has called on the Federal…
January 05, 2025

Northern elders call for suspension of Tinubu’s ‘draconian’ Tax Reform Bills

The Northern Elders Forum (NEF) has urged the Federal Government to suspend the implementation of…
January 04, 2025

How to read people like a book, according to body language experts

Alan England Have you ever wanted to know what someone’s thinking, or what their motives…
January 04, 2025

Shy man cuts off 4 fingers instead of telling boss he wanted to quit his…

A 32-year-old Indian man admitted to cutting off four fingers on his left hand to…
December 27, 2024

Christmas Day attack on Benue community claims 11 lives

At least 11 people have been reportedly killed in Tor Azege community in Kwande Local…
January 06, 2025

Here’s the latest as Israel-Hamas war enters Day 458

Hamas and Israel wrangle over talks as Israeli strikes in Gaza intensify Israel and Hamas…
December 25, 2024

Stem cell therapy to correct heart failure in children could 'transform lives'

Renowned visionary English physician William Harvey wrote in 1651 about how our blood contains all…
December 17, 2024

Ademola Lookman named 2024 CAF Men’s Player of the year. These players won in other…

Ademola Lookman, the Super Eagles winger, was crowned the 2024 CAF Men’s Player of the…

NEWSSCROLL TEAM: 'Sina Kawonise: Publisher/Editor-in-Chief; Prof Wale Are Olaitan: Editorial Consultant; Femi Kawonise: Head, Production & Administration; Afolabi Ajibola: IT Manager;
Contact Us: [email protected] Tel/WhatsApp: +234 811 395 4049

Copyright © 2015 - 2025 NewsScroll. All rights reserved.