Technology
New WhatsApp bug may steal files, messages with GIFs
San Francisco, Oct 3
A security bug has been found in Facebook-owned instant messenger WhatsApp that could let attackers to obtain access to a device and steal data by sending a malicious GIF file.
The danger stems from a double-free bug in WhatsApp, according to a researcher going by the nickname Awakened, The Next Web reported on Wednesday.
A double-free vulnerability is a memory corruption anomaly that could crash an application or open up an exploit vector that attackers can abuse to gain access to users' device.
According to Awakened's post on GitHub, the flaw resided in WhatsApp's Gallery view implementation that is used to generate previews for photographs, videos and GIFs.
All it takes to perform the attack is to craft a malicious GIF, and wait for the user to open the WhatsApp gallery, the report added.
"The exploit works well until WhatsApp version 2.19.230. The vulnerability is officially patched in WhatsApp version 2.19.244," wrote the researcher.
The bug also works for Android 8.1 and Android 9.0 OS but does not work for Android 8.0 and below.
In the older Android versions, double-free could still be triggered. However, because of the malloc calls by the system after the double-free, the app just crashes before reaching to the point that we could control the PC register, according to a report in Gizmodo.
The danger stems from a double-free bug in WhatsApp, according to a researcher going by the nickname Awakened, The Next Web reported on Wednesday.
A double-free vulnerability is a memory corruption anomaly that could crash an application or open up an exploit vector that attackers can abuse to gain access to users' device.
According to Awakened's post on GitHub, the flaw resided in WhatsApp's Gallery view implementation that is used to generate previews for photographs, videos and GIFs.
All it takes to perform the attack is to craft a malicious GIF, and wait for the user to open the WhatsApp gallery, the report added.
"The exploit works well until WhatsApp version 2.19.230. The vulnerability is officially patched in WhatsApp version 2.19.244," wrote the researcher.
The bug also works for Android 8.1 and Android 9.0 OS but does not work for Android 8.0 and below.
In the older Android versions, double-free could still be triggered. However, because of the malloc calls by the system after the double-free, the app just crashes before reaching to the point that we could control the PC register, according to a report in Gizmodo.
1 hour ago
Huge LPG shortage in country, Modi govt's 'feeble' foreign policy to blame: Kejriwal
1 hour ago
PM Modi launches Rs 10,800 crore development push in Kerala
2 hours ago
Priya Dutt shares throwback pictures of Sunil Dutt, Nargis on their marriage anniversary: Love thrives in patience, respect,
2 hours ago
Devoleena Bhattacharjee recalls time caring for her mother’s schizophrenia attacks from a young age of 1
2 hours ago
Pooja Batra enjoys golden sunset: Transports me to a different vibe
2 hours ago
Rajkummar Rao recalls late mother’s teachings in emotional note on her 10th death anniversary
2 hours ago
Khushboo Sundar on World Cup trophy being taken to temple: The trophy is for India
2 hours ago
Sona Mohapatra slams Badshah over song 'Tateeree': Artists shape imagination
2 hours ago
CM Vijayan urges Centre to ensure LPG supply and price relief
2 hours ago
Bihar Police issues alert to prevent hoarding of petrol, LPG
2 hours ago
PM Modi courts fishers at Dheevara Sabha celebrations, hails community’s role in Kerala’s growth
2 hours ago
Wild things said about me, says Rahul Gandhi after Prasad speaks on LoP's responsibilities
2 hours ago
Scramble among Congress MPs for Assembly seats as they sense victory ahead in Kerala polls
