Security vulnerability fixed in WhatsApp’s image filter function


PTI, Sep 3, 2021, 12:12 PM IST

Source: unsplash

Check Point Research (CPR) on Thursday, September 2, said it had flagged a security vulnerability in WhatsApp’s image filter function that could have been exploited by attackers to read sensitive information, and the same has now been fixed by the messaging platform.

“CPR exposed a security vulnerability in WhatsApp…An attacker could have exploited the vulnerability to read sensitive information from WhatsApp memory,” CPR said in a statement.

It added that the vulnerability was rooted in WhatsApp’s image filter function and during its research study, CPR learned that switching between various filters on crafted GIF files caused WhatsApp to crash.

“CPR identified one of the crashes as memory corruption. CPR promptly reported the problem to WhatsApp, who named for the vulnerability CVE-2020-1910, detailing it as an out-of-bounds read and write issue,” it noted.

Successful exploitation of the vulnerability would have required an attacker to apply specific image filters to a specially crafted image and send the resulting image, it added.

With over two billion active users, WhatsApp can be an attractive target for attackers. Once we discovered the security vulnerability, we quickly reported our findings to WhatsApp, which was cooperative and collaborative in issuing a fix. The result of our collective efforts is a safer WhatsApp for users worldwide, Check Point Head of Products Vulnerabilities Research Oded Vanunu said.

When contacted, a WhatsApp spokesperson said the company regularly works with security researchers “to improve the numerous ways WhatsApp protects people’s messages, and we appreciate the work that Check Point does to investigate every corner of our app”.

“CPR identified one of the crashes as memory corruption. CPR promptly reported the problem to WhatsApp, who named for the vulnerability CVE-2020-1910, detailing it as an out-of-bounds read and write issue,” it noted.

Successful exploitation of the vulnerability would have required an attacker to apply specific image filters to a specially crafted image and send the resulting image, it added.

With over two billion active users, WhatsApp can be an attractive target for attackers. Once we discovered the security vulnerability, we quickly reported our findings to WhatsApp, which was cooperative and collaborative in issuing a fix. The result of our collective efforts is a safer WhatsApp for users worldwide, Check Point Head of Products Vulnerabilities Research Oded Vanunu said.

When contacted, a WhatsApp spokesperson said the company regularly works with security researchers “to improve the numerous ways WhatsApp protects people’s messages, and we appreciate the work that Check Point does to investigate every corner of our app”.

Udayavani is now on Telegram. Click here to join our channel and stay updated with the latest news.

Top News

Shivakumar desperately wants to become CM, says K’taka BJP chief Vijayendra

M’luru: Hotelier approaches consumer court after car filled with diesel instead of petrol

CET 2024: At least 45 questions out of syllabus, claim students

‘Out of control’ lorry hits several vehicles, shops after ‘brake failure’ at Yedapadavu

RCB helps restore three Bengaluru lakes; chips in to solve water crisis

Elderly tourist from Bengaluru goes missing in Goa

Bengaluru’s Shift to Smarter Spending: Pre-Owned Car Sales Jump 87 percent

Related Articles More

Can AI Read Our Minds? And Should We Be Worried About It?

India aims to achieve debris-free space missions by 2030: ISRO chief Somanath

Will AI help or hinder trust in science?

AI, once a research subject, today a reality!

IIT-Madras, NPTEL launch technical courses in vernacular languages

MUST WATCH

Grafting Jack Anil

Heat Illness

Dwarakish death at 81

H. D. Deve Gowda

Aura Cake shop in udupi


Latest Additions

Shivakumar desperately wants to become CM, says K’taka BJP chief Vijayendra

Scribe throws lapel microphone towards Sharad Pawar in Baramati; cops give clean chit

India delivers first batch of BrahMos missiles to Philippines

Air India cancels Dubai flights due to operational disruptions

2 Indian students killed in Scottish waterfall accident

Thanks for visiting Udayavani

You seem to have an Ad Blocker on.
To continue reading, please turn it off or whitelist Udayavani.