Latest News

    WhatsApp Bug Allows Malicious Code-Injection, One-Click RCE
    Friday, February 7, 2020 IST
    WhatsApp Bug Allows Malicious Code-Injection, One-Click RCE

    A high-severity vulnerability could allow cybercriminals to push malware or remotely execute code, using seemingly innocuous messages.

     
     

    Security researchers have identified a JavaScript vulnerability in the WhatsApp desktop platform that could allow cybercriminals to spread malware, phishing or ransomware campaigns through notification messages that appear completely normal to unsuspecting users. And, further investigation shows this could be parlayed into remote code-execution.
     
    The desktop platform has more than 1.5 billion monthly active users. The high-severity bug (rated 8.2 on the CVSS severity scale) could impact those that also use WhatsApp for iPhone, if they don’t update their desktop and mobile apps, and if they don’t use newer versions of the Chrome browser.
     
    “A vulnerability [CVE-2019-1842] in WhatsApp Desktop versions prior to 0.3.9309 when paired with WhatsApp for iPhone versions prior to 2.20.10 allows cross-site scripting (XSS) and local file reading,” according to the National Vulnerability Database. “Exploiting the vulnerability requires the victim to click a link preview from a specially crafted text message.”
     
    More specifically, “The flaws leave users vulnerable to attacks by allowing both the text content and links in website previews to be tampered with to display false content and modified links that point to malicious destinations,” PerimeterX founder and CTO Ido Safruti wrote in a blog post, on Tuesday.
     
    Bad actors can inject harmful code or links into “seemingly innocuous exchanges,” according to Safruti, causing unsuspecting users to click on malicious links that appear to them like messages from a friend.
     
    “These message modifications would be completely invisible to the untrained eye,” he wrote. “Such attacks would be possible by simply modifying the JavaScript code of a single message prior to delivery to its recipient.”
     
    However, the end game is remote code-execution — a potential outcome in some browsers, according to the researchers.
     
    Bug Details
     
    PerimenterX cybersecurity researcher and JavaScript expert Gal Weizman first discovered vulnerabilities leading to this latest bug in WhatsApp in 2017. He broke down the journey to discovering the latest flaw and its potential for leading to RCE in a separate post. He also said he has been working with Facebook, which owns and oversees WhatsApp, to fix the issues.
     
    In his breakdown, Weizman showed how he  started by tampering with the JavaScript for the rich preview banners of messages—the ones that include extra information regarding a link that is in the body of the message.
     
     
    Through the WhatsApp desktop platform, Weizman was able to find the code where messages are formed, tamper with it and then let the app continue in its natural message-sending flow. This bypassed filters and sent the modified message through the app as usual, appearing relatively normal in the user interface. Weizman also found that website previews, displayed when users share web links, can also be tampered with before being shown.
     
    In this way, it’s possible to inject links that redirect a user to malicious web pages or that initiate malware downloads. Further, the researcher discovered that he could also make those links look like authentic domain links — i.e., as if they really come from Facebook or other legitimate website.

     
     
     
     
     

    Related Topics

     
     
     

    Trending News & Articles

     Article
    Tata Harrier’s 7-seater Version H7X Will Be Quite Different – Report

    Tata Harrier’s three-row seat version in works, details out  

    Recently posted . 2K views . 0 min read
     

     Article
    How to make you car as silent as a Rolls Royce inside

    Rolls Royce cars are extremely luxurious. While there are many expensive pieces of equipment in Rolls Royce cars, their most relaxing feature is the silence that ...

    Recently posted . 2K views . 2 min read
     

     Article
    India's Top 5 Mobile Charger manufacturer Brand 2019

    The following list of India's Top 5 Mobile Charger manufacture Brand 2019  

    Recently posted . 2K views . 0 min read
     

     Article
    Mahindra XUV300 vs Maruti Brezza, Ford EcoSport, Tata Nexon – Price

    XUV300 is the latest entrant in the compact SUV segment.

    Recently posted . 2K views . 0 min read
     

     
     

    More in Electronics & Gadgets

     Article
    With the launch of Intra, Tata Motors creates a compact truck segment

    Tata Motors on Wednesday launched a new range of compact truck, Tata Intra — a small commercial vehicle developed under the modular platform. The company cl...

    Recently posted. 1K views . 2 min read
     

     Article
    WhatsApp Stickers Now Official Along With a Dedicated Stickers Store

    After months of anticipation and some initial rumours and leaks, WhatsApp has now finally brought stickers. The sticker integration is initially limited to WhatsA...

    Recently posted. 885 views . 4 min read
     

     Article
    Triumph Speed Twin vs Rivals: Price Comparison

    Triumph Motorcycles India has launched the Speed Twin at a price of Rs. 9.46 lakh (ex-showroom) which we believe, is aggressive pricing. And here is a quick compari...

    Recently posted. 1K views . 1 min read
     

     Video
    Folding Garage ideas



    Recently posted . 900 views
     

     Reviews
    Canon EOS 1500D Review



    Recently posted . 1K views . 77 min read
     

     Article
    All-New Hyundai Santro Hatchback Officially Unveiled in India, Bookings to Open at Rs 11,100

    The all-new 2018 Hyundai Santro gets segment firsts like rear AC vents and a 17.64 cm (6.94-inch) touchscreen audio video system. Bookings for the hatchback open ...

    Recently posted. 758 views . 1 min read
     

     Article
    Honeywell developing software to decode 100 Indian accents to make flying safer

    Honeywell, the New Jersey-based conglomerate, at the behest of the government, is developing software that will decipher pilots’ accents and automatically tra...

    Recently posted. 711 views . 1 min read
     

     
     
     

       Prashnavali

      Thought of the Day

    “Your smile is the prettiest thing you’ll ever wear.”
    Anonymous

    Be the first one to comment on this story

    Close
    Post Comment
    Shibu Chandran
    2 hours ago

    Serving political interests in another person's illness is the lowest form of human value. A 70+ y old lady has cancer.

    November 28, 2016 05:00 IST
    Shibu Chandran
    2 hours ago

    Serving political interests in another person's illness is the lowest form of human value. A 70+ y old lady has cancer.

    November 28, 2016 05:00 IST
    Shibu Chandran
    2 hours ago

    Serving political interests in another person's illness is the lowest form of human value. A 70+ y old lady has cancer.

    November 28, 2016 05:00 IST
    Shibu Chandran
    2 hours ago

    Serving political interests in another person's illness is the lowest form of human value. A 70+ y old lady has cancer.

    November 28, 2016 05:00 IST


    ads
    Back To Top