Two Indian researchers, Indrajeet Bhuyan and Saurav Kar, both
17-year old teenagers demonstrated the WhatsApp Message Handler
vulnerability.
message ( greater than 7mb in size) on WhatsApp could crash victim device and app immediately, but using this new exploit attacker only need to send a very small size (approx 2kb) message to the victim.
The worried
impact of the vulnerability is that the user who received the specially crafted
message will have to delete his/her whole conversation and start a fresh chat,
because opening the message keeps on crashing WhatsApp unless the chat is
deleted completely.
According to that, the reported vulnerability has been tested and
successfully works on most of the versions of Android Operating system including Kitkat, Jellybean and all the lower android versions.
Similarly, Any member of your WhatsApp group could intentionally
send a specially crafted message to exit people from the group and delete the
group. Also, for example, if I don’t want someone to keep records of my chat
with them, then I can also send the same message exploit to the person.
The vulnerability has not been tested on iOS, but it is sure that all versions of WhatsApp including 2.11.431 and 2.11.432 are affected with this bug. Also the attack does not work on Windows 8.1.
Comments
Post a Comment