A new vulnerability discovered in popular messaging services like WhatsApp and Telegram lets hackers assume complete control over accounts.
A newly discovered vulnerability within WhatsApp Web and Telegram Web, online platforms for two popular messaging services, lets cybercriminals fully take over user accounts and access conversations, photos, videos, contact lists, and other shared files.
The flaw lets hackers send their victims malicious code disguised within a seemingly innocent picture. When victims click the image, attackers have access to all of their storage data and can spread the harmful file through users' contact lists.
Both WhatsApp and Telegram employ end-to-end message encryption so only the participants in a conversation can view messages. This data security measure was the source of the vulnerability. Because content was encrypted on the sender's side, the two platforms did not see the content and couldn't prevent harmful files from being sent.
Check Point researchers revealed the vulnerability and disclosed its findings to the WhatsApp and Telegram security teams on March 8. Now content will be checked pre-encryption to stop malicious files from being sent.
Read more here.
About the Author(s)
You May Also Like
The fuel in the new AI race: Data
April 23, 2024Securing Code in the Age of AI
April 24, 2024Beyond Spam Filters and Firewalls: Preventing Business Email Compromises in the Modern Enterprise
April 30, 2024Key Findings from the State of AppSec Report 2024
May 7, 2024Is AI Identifying Threats to Your Network?
May 14, 2024
Black Hat USA - August 3-8 - Learn More
August 3, 2024Cybersecurity's Hottest New Technologies: What You Need To Know
March 21, 2024