Thursday, March 27th, 2025

New WhatsApp bug may steal files, messages with GIFs


03 October 2019  

Time taken to read : 2 Minute


  • A
  • A
  • A

SAN FRANCISCO: A security bug has been found in Facebook-owned instant messenger WhatsApp that could let attackers obtain access to a device and steal data by sending a malicious GIF file.

The danger stems from a double-free bug in WhatsApp, according to a researcher going by the nickname Awakened, The Next Web reported on Wednesday.

A double-free vulnerability is a memory corruption anomaly that could crash an application or open up an exploit vector that attackers can abuse to gain access to users’ devices.

According to Awakened’s post on GitHub, the flaw resided in WhatsApp’s Gallery view implementation that is used to generate previews for photographs, videos, and GIFs.

All it takes to perform the attack is to craft a malicious GIF, and wait for the user to open the WhatsApp gallery, the report added.

“The exploit works well until WhatsApp version 2.19.230. The vulnerability is officially patched in WhatsApp version 2.19.244,” wrote the researcher.

The bug also works for Android 8.1 and Android 9.0 OS but does not work for Android 8.0 and below.

In the older Android versions, double-free could still be triggered. However, because of the malloc calls by the system after the double-free, the app just crashes before reaching to the point that we could control the PC register, according to a report in Gizmodo.

(Agencies)

Publish Date : 03 October 2019 20:42 PM

RPP to continue protests, confirms participation in demonstration at Tinkune

KATHMANDU: The Rastriya Prajatantra Party (RPP), led by Rajendra Lingden,

Birgunj customs sees imports worth Rs 390 billion in eight months

BIRGUNJ: Imports amounting to over Rs 390 billion took place

NHRC urges peaceful protests

KATHMANDU: The National Human Rights Commission (NHRC) has called for

Mahesh Bartaula: Kulman’s case is in court, obstructing Parliament is unjustified

KATHMANDU: CPN-UML Chief Whip Mahesh Bartaula has stated that since

Protesters chant: Load shedding is not needed, Kulman cannot be removed

KATHMANDU: The Rastriya Prajatantra Party (RPP) has staged a protest