Technology
New WhatsApp bug may steal files, messages with GIFs
San Francisco, Oct 3
A security bug has been found in Facebook-owned instant messenger WhatsApp that could let attackers to obtain access to a device and steal data by sending a malicious GIF file.
The danger stems from a double-free bug in WhatsApp, according to a researcher going by the nickname Awakened, The Next Web reported on Wednesday.
A double-free vulnerability is a memory corruption anomaly that could crash an application or open up an exploit vector that attackers can abuse to gain access to users' device.
According to Awakened's post on GitHub, the flaw resided in WhatsApp's Gallery view implementation that is used to generate previews for photographs, videos and GIFs.
All it takes to perform the attack is to craft a malicious GIF, and wait for the user to open the WhatsApp gallery, the report added.
"The exploit works well until WhatsApp version 2.19.230. The vulnerability is officially patched in WhatsApp version 2.19.244," wrote the researcher.
The bug also works for Android 8.1 and Android 9.0 OS but does not work for Android 8.0 and below.
In the older Android versions, double-free could still be triggered. However, because of the malloc calls by the system after the double-free, the app just crashes before reaching to the point that we could control the PC register, according to a report in Gizmodo.
The danger stems from a double-free bug in WhatsApp, according to a researcher going by the nickname Awakened, The Next Web reported on Wednesday.
A double-free vulnerability is a memory corruption anomaly that could crash an application or open up an exploit vector that attackers can abuse to gain access to users' device.
According to Awakened's post on GitHub, the flaw resided in WhatsApp's Gallery view implementation that is used to generate previews for photographs, videos and GIFs.
All it takes to perform the attack is to craft a malicious GIF, and wait for the user to open the WhatsApp gallery, the report added.
"The exploit works well until WhatsApp version 2.19.230. The vulnerability is officially patched in WhatsApp version 2.19.244," wrote the researcher.
The bug also works for Android 8.1 and Android 9.0 OS but does not work for Android 8.0 and below.
In the older Android versions, double-free could still be triggered. However, because of the malloc calls by the system after the double-free, the app just crashes before reaching to the point that we could control the PC register, according to a report in Gizmodo.
2 hours ago
Rohit Shetty says ‘Golmaal 5’ will bring ‘laughter and joy’ on January 8, 2027
2 hours ago
Dhruv Vikram plays a stuntman in 'Jackie - No Retakes Allowed'!
2 hours ago
Swati Sharma on comparisons with Mouni Roy in ‘Kyunki Saas Bhi Kabhi Bahu Thi 2’
2 hours ago
Miley Cyrus reveals why ‘Redlights’ is one of her favorite records she’s released to date
2 hours ago
Vijay's son Jason Sanjay's 'Sigma' trailer promises a thrilling heist adventure
2 hours ago
Nani discloses his son is eager to watch 'The Paradise' but has been told he can't watch it when it releases, here's why!
2 hours ago
Munmun Dutta gives a glimpse of ‘Taarak Mehta Ka Ooltah Chashmah’ sets when nobody’s shooting: It looks haunted
2 hours ago
Bethlehem Kudumba Unit's co-writer Kiran Josey turns director with 'Picnic'
2 hours ago
Amitabh Bachchan shares life lesson: Small efforts can open doors
2 hours ago
Miley Cyrus is worried about post marriage ‘icks’ with Maxx Morando
2 hours ago
Lily Collins bids adieu to her ‘Emily in Paris’ character as the show presses button with final season
2 hours ago
One killed, 22 injured as lightning strikes football match in Bengal's Jhargram
2 hours ago
India's contribution to per capita carbon emissions less than half of global average: PM Modi
