WhatsApp fixes problem in image filter after CPR flagged security vulnerability : The Tribune India

Join Whatsapp Channel

WhatsApp fixes problem in image filter after CPR flagged security vulnerability

Successful exploitation of the vulnerability would have required an attacker to apply specific image filters to a specially crafted image and send the resulting image

WhatsApp fixes problem in image filter after CPR flagged security vulnerability

Photo for representation.



New Delhi, September 2

Check Point Research (CPR) on Thursday said it had flagged a security vulnerability in WhatsApp’s image filter function that could have been exploited by attackers to read sensitive information, and the same has now been fixed by the messaging platform.

“CPR exposed a security vulnerability in WhatsApp...An attacker could have exploited the vulnerability to read sensitive information from WhatsApp memory,” CPR said in a statement.

It added that the vulnerability was rooted in WhatsApp’s image filter function and during its research study, CPR learned that switching between various filters on crafted GIF files caused WhatsApp to crash.

“CPR identified one of the crashes as memory corruption. CPR promptly reported the problem to WhatsApp, who named the vulnerability CVE-2020-1910, detailing it as an out-of-bounds read and write issue,” it noted.

Successful exploitation of the vulnerability would have required an attacker to apply specific image filters to a specially crafted image and send the resulting image, it added.

“With over two billion active users, WhatsApp can be an attractive target for attackers. Once we discovered the security vulnerability, we quickly reported our findings to WhatsApp, which was cooperative and collaborative in issuing a fix. The result of our collective efforts is a safer WhatsApp for users worldwide,” Check Point Head of Products Vulnerabilities Research Oded Vanunu said.

When contacted, a WhatsApp spokesperson said the company regularly works with security researchers “to improve the numerous ways WhatsApp protects people’s messages, and we appreciate the work that Check Point does to investigate every corner of our app”.

“People should have no doubt that end-to-end encryption continues to work as intended and people’s messages remain safe and secure,” the spokesperson added. PTI


Top News

Security vehicle fired upon in J-K's Poonch; reinforcements rushed

One IAF soldier killed, 4 injured after terrorists ambush convoy in J-K's Poonch

Reinforcements from army and police have been rushed; massiv...

Karnataka sex scandal: JD(S) MLA HD Revanna taken into custody by SIT in kidnapping case

Karnataka sex scandal: JD(S) MLA HD Revanna taken into custody by SIT in kidnapping case

The former minister was picked up from his father and JD(S) ...

Lok Sabha election: Will Prajwal Revanna controversy affect BJP prospects in Karnataka

Lok Sabha election: Will Prajwal Revanna controversy affect BJP prospects in Karnataka

The BJP leadership is ‘worried to some extent’, say sources;...

Here is all about 3 Punjabi youth held in Canada for Khalistani activist Hardeep Nijjar’s killing?

Here is all about 3 Punjabi youth held in Canada for Khalistani activist Hardeep Nijjar’s killing

Karan Brar belongs to Kotkapura and his father Mandeep Singh...


Cities

View All