Skip to main content
  1. Home
  2. Social Media
  3. News

WhatsApp fixes bug that could have allowed hackers to read your desktop files

Add as a preferred source on Google
 

WhatsApp patched a security loophole in its desktop apps last month that could have potentially allowed hackers to access your computer’s local files. Discovered by a cybersecurity researcher at PerimeterX, the vulnerability affected the messaging service’s Windows and Mac clients when they were paired with an iPhone.

Recommended Videos

The flaw was found inside WhatsApp’s Content Security Policy, an extra security layer companies often employ to prevent a certain set of attacks and made possible for malicious actors to manipulate messages and links through a method called Cross-Site Scripting.

When a user would tap on one of these adulterated texts, they would unknowingly grant the attacker permissions to read their computer’s local files, as well as to inject malicious codes. While the vulnerability did require interaction from the user to function, it was possible to execute it remotely.

“A vulnerability in WhatsApp Desktop when paired with WhatsApp for iPhone allows cross-site scripting and local file reading. Exploiting the vulnerability requires the victim to click a link preview from a specially crafted text message,” parent company Facebook wrote in a security advisory.

The bug affects WhatsApp Desktop builds prior to v0.3.9309 and WhatsApp for iPhone versions prior to 2.20.10. It was fixed on 21st January 2020. Therefore, to ensure you’re safe, go ahead and update the WhatsApp app on your computer and iPhone.

“Older versions of Google Chrome’s Chromium framework, as used by the vulnerable versions of the WhatsApp desktop application, are susceptible to these code injections, although newer versions of Google Chrome have protections against such JavaScript modifications. Other browsers such as Safari are still wide open to these vulnerabilities,” explained PerimeterX’s founder and CTO, Ido Safruti.

The vulnerability doesn’t impact Android because unlike iOS, it has additional protections in place against Javascript banners. “iOS omitted this check, which enabled banners with malicious content to load on iOS devices,” added a PerimeterX spokesperson.

In the last year, WhatsApp has had a hard time keeping security vulnerabilities out. In November, the Facebook-owned messaging giant patched a flaw that could have let hackers take control of a phone with just an MP4 file. A few weeks back, it was found that that same bug also compromised Amazon’s Jeff Bezos’ phone and sensitive data. Telegram’s CEO later, in a scathing blog post, accused WhatsApp of deliberately planting backdoors for law enforcement agencies and masking them as bugs when caught.

Shubham Agarwal
Shubham Agarwal is a freelance technology journalist from Ahmedabad, India. His work has previously appeared in Firstpost…
The EU says TikTok still isn’t doing enough to protect kids
Regulators say the platform's privacy settings don't go far enough under the Digital Services Act.
TikTok Creative Featured

The European Commission has accused TikTok of falling short on protecting minors, saying the platform's current account settings don't meet the child safety standards required under the Digital Services Act (DSA). The findings are preliminary, but if upheld, TikTok could face a fine of up to 6% of its global annual revenue.

Why the EU thinks TikTok isn't doing enough

Read more
Facebook debuts Seller app for Marketplace and tests a TikTok-style video feed
As Marketplace turns ten, Facebook is celebrating with a seller app and a video-first redesign test.
facebook-seller-app

Facebook Marketplace just turned ten, and Meta is marking the milestone by reshaping how you buy, sell, and scroll. The company launched a dedicated app called Seller for its most active Marketplace users.

At the same time, it confirmed plans to test a video-first home screen that looks a lot like TikTok. Together, these updates hint at where Facebook wants to take its massive user base next, and they lean heavily on AI to get there.

Read more
Facebook is getting a free verified badge to help spot real people
No subscription, no catch, just a quick selfie to prove you're not a bot.
Facebook verified batch

AI has made it stupidly easy to fake being a real person online, so Facebook is rolling out a new badge to prove you're not one of them. It's called Facebook Verified, and the best part is that it won't cost you a thing.

How do you get verified on Facebook?

Read more