A security issue in the latest version of WhatsApp for Windowsallows sending Python and PHP attachments that execute without any warning when the recipient opens them.
See also: WhatsApp introduces a new album selection tool

For the attack to be successful, Python must be installed, a requirement that may limit targets to software developers, researchers, and experienced users.
The issue is similar to the one that affected Telegram for Windows in April, where attackers could bypass security warnings and perform remote code execution when sending a Python .pyzw through the messaging client.
WhatsApp blocks many file types that are considered to pose risks to users , but the company says it has no plans to add Python scripts to the list. Further testing shows that PHP (.php) files are also not included in WhatsApp's block list.
Python and PHP scripts are not blocked
Security researcher Saumyajeet Das found the vulnerability while experimenting with file types that could be attached to WhatsApp conversations, to see if the app allowed any of the dangerous ones.
When you send a potentially dangerous file, such as .EXE, WhatsApp displays it and gives the recipient two options: Open or Save as.
See also: WhatsApp: Tests new file transfer feature, similar to Apple's AirDrop
However, when trying to open the file, WhatsApp for Windows throws an error, leaving users with only the option to save the file to disk and launch it from there. Das found that WhatsApp also blocks the execution of .DLL, .HTA, and VBS.
Das said he found three file types that the WhatsApp client does not block from launching: .PYZ (Python ZIP application), .PYZW (PyInstaller program) , and .EVTX (Windows event log file).

BleepingComputer's tests confirmed that WhatsApp does not block the execution of Python files and discovered that the same is true for PHP scripts.
If all the resources are present, all the recipient needs to do is click the “Open” button on the downloaded file and the script runs immediately.
Das reported the problem to Meta on June 3, and the company responded on July 15, saying that the issue had already been reported by another researcher.
A WhatsApp spokesperson explained that they do not see the execution of Python files as a problem on their side, so there are no plans for a fix:
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
“We have read what the researcher has suggested and appreciate their submission. Malware can take many different forms, including through downloadable files intended to trick a user.“
“That's why we warn users to never click or open a file from someone they don't know, regardless of how they received it — whether through WhatsApp or any other app.“
The company spokesperson also explained that WhatsApp has a system that warns users when they are being messaged by users who are not in their contact lists or when they have phone numbers registered in a different country.
See also: Vietnamese hackers behind WhatsApp e-challan scam in India
WhatsApp is a widely used messaging app that allows users to send text messages, voice notes, make voice and video calls, and share images, documents, and other media. encryption ensures that messages are secure and can only be read by the sender and recipient, making it a popular choice for both personal and professional communication. With features like group chats and status updates, WhatsApp facilitates connections between friends, family, and colleagues, transcending geographical boundaries and enhancing social interactions in the digital age.
Source: bleepingcomputer
