A new vulnerability discovered in popular messaging services like WhatsApp and Telegram lets hackers assume complete control over accounts.
A newly discovered vulnerability within WhatsApp Web and Telegram Web, online platforms for two popular messaging services, lets cybercriminals fully take over user accounts and access conversations, photos, videos, contact lists, and other shared files.
The flaw lets hackers send their victims malicious code disguised within a seemingly innocent picture. When victims click the image, attackers have access to all of their storage data and can spread the harmful file through users' contact lists.
Both WhatsApp and Telegram employ end-to-end message encryption so only the participants in a conversation can view messages. This data security measure was the source of the vulnerability. Because content was encrypted on the sender's side, the two platforms did not see the content and couldn't prevent harmful files from being sent.
Check Point researchers revealed the vulnerability and disclosed its findings to the WhatsApp and Telegram security teams on March 8. Now content will be checked pre-encryption to stop malicious files from being sent.
Read more here.
About the Author(s)
You May Also Like
Guarding the Cloud: Top 5 Cloud Security Hacks and How You Can Avoid Them
April 4, 2024Cybersecurity Strategies for Small and Med Sized Businesses
April 11, 2024Defending Against Today's Threat Landscape with MDR
April 18, 2024Securing Code in the Age of AI
April 24, 2024
Black Hat USA - August 3-8 - Learn More
August 3, 2024Cybersecurity's Hottest New Technologies: What You Need To Know
March 21, 2024Black Hat Asia - April 16-19 - Learn More
April 16, 2024