Skip to main content
  1. Home
  2. Phones
  3. Mobile
  4. News

Your WhatsApp chats were vulnerable to attacks for months due to GIF exploit

Add as a preferred source on Google

WhatsApp has patched a critical security loophole that left your private messages and media vulnerable to breaches. The bug allowed attackers to remotely access your phone’s storage and all the files it hosts including your WhatsApp texts, pictures, videos, GIFs, and audio messages.

In order to exploit the bug, a hacker simply had to send you a malicious payload masquerading as a GIF through any non-Facebook channels or as a document through WhatsApp and Messenger. That is because, on the latter platforms, Facebook’s compression distorts the malware’s content.

Recommended Videos

The vulnerability existed inside a library that WhatsApp (and a whole lot of other apps) uses to preview a GIF. The library’s functions kick in whenever you tap the attach-media button and WhatsApp loads a grid of thumbnails. Therefore, you don’t even need to open the GIF to trigger the fraudulent code. It automatically activates when WhatsApp attempts to show its thumbnail even when you’re looking for another picture, video, or GIF.

Spotted originally by a Vietnamese security researcher, Pham Hong Nhat, the loophole remained unpatched for about three months.

Hong Nhat reported it to Facebook back in late July and the social media giant company rolled out the fix through WhatsApp version 2.19.244 in September. So in case you haven’t updated WhatsApp in a while, we recommend you go ahead and do it right away from the Play Store.

The issue only affected Android phones running on Android 8.1 or above and none of the iOS versions. It’s bewildering as to why it exclusively impacted the recent Android builds that, in theory, have better privacy frameworks in place. Ironically, Pham Hong Nhat says the older versions employ an outdated code that prevented the payload from being able to execute.

Fortunately, the developer behind the library in question — Android GIF Drawable — has released a patch as well. Hence, the vulnerability most likely won’t expose your data on the rest of the apps which use it for parsing GIFs.

Earlier last month, another WhatsApp vulnerability was discovered by Google’s security research team. The bug enabled attackers to take over iOS users’ WhatsApp chats by sending them malicious links.

Shubham Agarwal
Shubham Agarwal is a freelance technology journalist from Ahmedabad, India. His work has previously appeared in Firstpost…
TSMC might set up a price hike that could come straight for your next phone, laptop, or tablet
Here's what TSMC's rumored 10% chip price increase actually means in dollar terms, and why your next phone or laptop could end up costing more.
TSMC Fab

My wallet flinched the second I saw the words "TSMC" and "price increase" in the same headline, and honestly, yours should too.

Turns out the company behind the silicon powering basically every flagship device out there, including Apple’s A-series and Qualcomm’s Snapdragon processors, is reportedly about to make all of it a little pricier.

Read more
Samsung’s free storage doubling for preorders is gone in Austria, and the replacement isn’t as sweet
Samsung's free storage doubling deal might just be history.
The back of the Galaxy Z Fold 7

If you've pre-ordered a Samsung foldable purely for the free storage bump, tomorrow's Unpacked event might sting a little.

For years, pre-ordering a new Galaxy meant automatically getting double the storage at no additional charge. Buy the 128GB model, walk away with 256GB for the same price. The same applied to the 256GB and 512GB models. However, that might change at the upcoming Galaxy Unpacked event. 

Read more
Apple fixes Hide My Email bug that exposed users’ real email addresses
Here's how Apple's Hide My Email flaw leaked real addresses for over a year, and why it only got fixed once the story went public.
apple-merging-sign-in-with-apple-hide-my-email-icloud+

Turns out the "Hide" part of Hide My Email wasn't doing its job quite as advertised, something that I covered early in July. Security researcher Tyler Murphy reported the flaw in June 2025, but despite Apple claiming it was resolved in March 2026, independent tests confirmed it remained exploitable, at least until July 3, 2026.

So how did this bug actually work?

Read more