Monday 18 November 2019

WhatsApp has identified a vulnerability of a malicious MP4 file.



WhatsApp has identified a vulnerability that could have been exploited through a malicious MP4 file. India’s Computer Emergency Response Team (Cert-in) described the vulnerability’s severity rating as “high” and advised users to update to the latest version of WhatsApp.The vulnerability affected both Android and iOs systems. The company has rolled out a security update. “WhatsApp is constantly working to improve security. In this instance, there is no reason to believe users were impacted,” WhatsApp said in a statementon Sunday. The development comes just weeks after WhatsApp sued the Israeli company, NSO Group, over alleged misuse of their spyware Pegasus, which was installed in 1,400 users’ phones, including at least 120 Indians.In a post on its securities and advisory page, WhatsApp's parent company Facebook confirmed the vulnerability on November 14. The Certin website gives more details.“A remote attacker could send a specially crafted MP4 file to the target system. This could trigger a buffer overflow leading to the execution of arbitrary code by the attacker. The exploitation does not require authentication from the victim,” the website says.Cert-in says successful exploitation of the glitch could allow an attacker to cause “Remote Code Execution (RCE) or Denial of Service (DoS) condition, which could further compromise the system.

No comments:

Post a Comment