HomeSecurityFlaw in WhatsApp allows access to local file system

WhatsApp flaw allows access to local file system

WhatsApp

A critical vulnerability discovered in the WhatsApphas been patched by Facebook. The vulnerability could have allowed an attacker to gain access to files in the local file system, on both Windows and macOS devices.

All versions of WhatsApp Desktop before v0.3.9309 are affected by this vulnerability when combined with versions of WhatsApp for iPhone before 2.20.10.

The flaw, which has been dubbed CVE-2019-18426, has been rated 8.2 in terms of severity, but while it could be exploited remotely, it also requires user interaction to be successful.

A PerimeterX researcher, Gal Weizman, first discovered the flaw when he found a loophole in WhatsApp's Content Security Policy.

By testing his discovery, Weizman was able to gain access to the local file system on both Windows and MacOS devices.

The researcher says that theoretically “if you are running an old version of a vulnerable application, someone could exploit that vulnerability and do bad things to you.”

Before Facebook patched the vulnerability, it could have allowed attackers to insert malicious code and links into messages sent to unsuspecting users.

You can see a more detailed explanation of how the vulnerability works and how it was discovered here.

Facebook has fixed a bug in WhatsApp that could have been used to stop the app from working on the phones of group members and another that allowed attackers to modify or replace media files from a device's external storage before the recipient could view them.

Another critical vulnerability discovered in WhatsApp, on both Android and iOS, that could cause the app to crash when a user answered a call, was patched in October 2018. Meanwhile, a flaw discovered by CheckPoint was used by Weizman as inspiration for his research.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr/politiki-syntaxis/
Member of the Editorial Team of SecNews. He writes about cybersecurity, online fraud, privacy and technology. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS