Skip to main content
  1. Home
  2. Social Media
  3. News

WhatsApp fixes bug that could have allowed hackers to read your desktop files

Add as a preferred source on Google
 

WhatsApp patched a security loophole in its desktop apps last month that could have potentially allowed hackers to access your computer’s local files. Discovered by a cybersecurity researcher at PerimeterX, the vulnerability affected the messaging service’s Windows and Mac clients when they were paired with an iPhone.

Recommended Videos

The flaw was found inside WhatsApp’s Content Security Policy, an extra security layer companies often employ to prevent a certain set of attacks and made possible for malicious actors to manipulate messages and links through a method called Cross-Site Scripting.

When a user would tap on one of these adulterated texts, they would unknowingly grant the attacker permissions to read their computer’s local files, as well as to inject malicious codes. While the vulnerability did require interaction from the user to function, it was possible to execute it remotely.

“A vulnerability in WhatsApp Desktop when paired with WhatsApp for iPhone allows cross-site scripting and local file reading. Exploiting the vulnerability requires the victim to click a link preview from a specially crafted text message,” parent company Facebook wrote in a security advisory.

The bug affects WhatsApp Desktop builds prior to v0.3.9309 and WhatsApp for iPhone versions prior to 2.20.10. It was fixed on 21st January 2020. Therefore, to ensure you’re safe, go ahead and update the WhatsApp app on your computer and iPhone.

“Older versions of Google Chrome’s Chromium framework, as used by the vulnerable versions of the WhatsApp desktop application, are susceptible to these code injections, although newer versions of Google Chrome have protections against such JavaScript modifications. Other browsers such as Safari are still wide open to these vulnerabilities,” explained PerimeterX’s founder and CTO, Ido Safruti.

The vulnerability doesn’t impact Android because unlike iOS, it has additional protections in place against Javascript banners. “iOS omitted this check, which enabled banners with malicious content to load on iOS devices,” added a PerimeterX spokesperson.

In the last year, WhatsApp has had a hard time keeping security vulnerabilities out. In November, the Facebook-owned messaging giant patched a flaw that could have let hackers take control of a phone with just an MP4 file. A few weeks back, it was found that that same bug also compromised Amazon’s Jeff Bezos’ phone and sensitive data. Telegram’s CEO later, in a scathing blog post, accused WhatsApp of deliberately planting backdoors for law enforcement agencies and masking them as bugs when caught.

Shubham Agarwal
Shubham Agarwal is a freelance technology journalist from Ahmedabad, India. His work has previously appeared in Firstpost…
Child abuse material continues to surface on X despite Elon Musk’s promises
New investigation claims several previously flagged child abuse images were found on X.
X-logo

Elon Musk once called removing child sexual abuse material from X his top priority. Yet new investigations suggest the platform still struggles to keep known abusive content offline. Reviews by The New York Times and the Canadian Center for Child Protection found previously flagged material on X, while Grok generated sexualized images involving children earlier this year.

Grok generated images involving known abuse victims

Read more
Researchers warn that social media can reveal sensitive details about users
Social media activity can reveal your politics, religion, and shopping habits, researchers warn
Social Media

What you post online is only part of the story. A new review of research into social media privacy warns that platforms and third parties can potentially infer sensitive details about people from seemingly ordinary digital activity, including their political opinions, religious leanings and shopping habits.

The findings, as reported by Techxplore, published in the International Journal of Management Concepts and Philosophy, point to a widening gap between the amount of personal information generated online and the legal and ethical protections designed to safeguard it. The researchers examined privacy breaches, regulatory frameworks, and the responsibilities of both social media companies and their users.

Read more
Instagram scammers are holding creators’ accounts hostage with copyright strikes
Meta’s copyright system is being weaponized against the creators it’s supposed to protect
A person holding a phone with the Instagram app open on it.

Imagine waking up to find your Instagram account suspended because someone claims you stole their content. You might know that the claim is false, but appealing it could take weeks. If you're a content creator, each day offline could cost you money. Meanwhile, the person behind the complaint offers to make the problem disappear for just a few hundred dollars.

According to a new BBC investigation, Instagram creators are being hit with this new online racket. Scammers are filing bogus copyright complaints and demanding payment to withdraw them, exploiting the fact that repeated claims can put an account at risk of suspension. The account owner may still have their password and login credentials, but that does little good when their content or account has been taken offline.

Read more