
A new vulnerability discovered by Symantec researchers in Telegram and WhatsApp could allow hackers to change the images and audio files that users of these apps see, despite their end-to-end encryption.
So while the sender might have sent a photo of a map to give someone directions, for example, a hacker could change the content and give incorrect directions. In the same way, a photo of an invoice could also be tampered with to send money to another account.
Secure apps are an important tool for activists, politicians, and dissidents who don't want their conversations monitored by anyone. Messaging apps like Signal, WhatsApp, Telegram, and iMessage have end-to-end encryption, meaning their conversations are secured even by the companies themselves.
However, while encryption protects conversations, the apps themselves can be vulnerable to hacking. Just last May, a vulnerability discovered in WhatsApp allowed hackers to install spyware on devices with a simple phone call, while in 2017, a vulnerability in Telegram allowed hackers to take control of accounts.
The new vulnerability, which was revealed on Monday, does not allow account takeover, but it does allow file tampering.
According to report , the vulnerability arose from the way files are stored in the WhatsApp and Telegram applications. When files are stored on external storage, other applications also have access to manipulate them. Regarding WhatsApp, files are stored externally by default, while in Telegram, the vulnerability occurs if the "Save to Gallery" option is enabled.

Symantec researchers tested malware created to manipulate image and audio files sent via WhatsApp and Telegram. In their test, the researchers sent a photo of two friends and the malware automatically replaced their faces with actor Nicolas Cage.
If you use one of these apps, you can protect yourself from this vulnerability by changing your storage settings. In WhatsApp, go to settings and disable the “Media Visibility” option, while in Telegram you can protect yourself by disabling the “Save to Gallery” option.
Symantec researchers also discovered a separate issue in Telegram, with a fake version of the app on the Google Play Store.
The app, called MobonoGram, is promoted as an improved version of Telegram with additional features. Instead, it includes malicious sites and pornographic content. It also slows down users' devices and reduces battery life.
The fraudulent app was downloaded more than 100,000 times before it was removed from the Google Play Store. Google confirmed that it had been removed and said it had blocked its developers.
