Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Mobile

Flaws in Telegram & WhatsApp on Android Put Data at Risk

App settings combined with Android behavior can put data integrity at risk for WhatsApp and Telegram users.

WhatsApp and Telegram are personal messaging apps that have, between them, more than 1.7 billion users around the world. They are frequently used by political activists, healthcare providers, and businesses around the world because of the security of their "always encrypted" communications. But recent research shows that there are security vulnerabilities that could open the services to manipulation and data theft for users on Android devices.

In a blog post today, Symantec researchers Yair Amit and Alon Gat discussed a media file jacking flaw in the way that the Android apps store files that the user receives. The researchers note that the flaw isn't in the app code, but in the app logic, specifically where the apps will store files that they receive.

"We found the vulnerability in the way on Android that WhatsApp (by default) and Telegram (in a certain setting) can store attachments like photos and audio messages before the user is able to open the original file," says Domingo Guerra, senior director of modern OS security at Symantec.

The trouble is that Android can store files in two locations — internal and external storage. Data in internal storage can only be accessed by the app that stored it. Data in external storage is defined as world readable and writeable — any app or user can read and modify the data.

WhatsApp stores received media files in external storage by default. Telegram uses external storage for its "Save to Gallery" feature. In both cases, the files are stored to publicly accessible directories.

According to Guerra, there are several kinds of damage that could result from the ability to intercept and manipulate files on an Android device — damage beyond the simple ability to see what sort of files are being sent back and forth between users.

In the blog post on the vulnerability, the researchers point out image manipulation, in which faces are changed or individuals inserted into images; audio manipulation, in which a "deepfake" technology makes it seem an individual is saying something they never actually said; invoice manipulation, in which the amount and payment details in a legitimate invoice are changed to send money into the attacker's account; and "fake news," in which the material sent out by a legitimate news organization is changed to become inaccurate, as possible harm from media file jacking.

To add to the vulnerability's seriousness, "You don't have to attack Telegram or WhatsApp for this to happen," says Guerra. "A device that already has malware that's monitoring for external storage could be vulnerable to replaced documents."

The apps' global footprints mean that the potential impact of these vulnerabilities. For example, Otavio Freire, CTO and president of SafeGuard Cyber, says, "In South America two years ago, doctors didn't use WhatsApp to communicate at all. Now, the adoption is 90% of Brazilian doctors who use WhatsApp for daily business."

And Freire says that more companies will be — and should be — using WhatsApp, Telegram, and other messaging apps going forward. "Companies that come to WhatsApp have come to it because it has significantly impacted their business processes," he says. "They do better marketing. They do better sales. They do better customer service. That's where the customers are, so if you ignore it, you're not where your customers are."

As for protection against the vulnerabilities, both Guerra and Freire say that some steps will be up the individual device owners — like setting WhatsApp to store files in internal storage and not using the "Gallery" function of Telegraph.

In addition, Freire points to the importance of saving archival copies of any corporate information transmitted by either app (or other messaging apps). In an era that sees the possibility of "deepfakes," they are necessary insurance against unwanted information going out to employees or customers.

Related content:

 

Black Hat USA returns to Las Vegas with hands-on technical Trainings, cutting-edge Briefings, Arsenal open-source tool demonstrations, top-tier security solutions, and service providers in the Business Hall. Click for information on the conference and to register.

Curtis Franklin Jr. is Senior Editor at Dark Reading. In this role he focuses on product and technology coverage for the publication. In addition he works on audio and video programming for Dark Reading and contributes to activities at Interop ITX, Black Hat, INsecurity, and ... View Full Bio

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
tonny123
50%
50%
tonny123,
User Rank: Apprentice
7/16/2019 | 2:00:20 AM
Netgear Router issues
very nice
Microsoft Patches Wormable RCE Vulns in Remote Desktop Services
Kelly Sheridan, Staff Editor, Dark Reading,  8/13/2019
The Mainframe Is Seeing a Resurgence. Is Security Keeping Pace?
Ray Overby, Co-Founder & President at Key Resources, Inc.,  8/15/2019
GitHub Named in Capital One Breach Lawsuit
Dark Reading Staff 8/14/2019
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Write a Caption, Win a Starbucks Card! Click Here
Latest Comment: This comment is waiting for review by our moderators.
Current Issue
7 Threats & Disruptive Forces Changing the Face of Cybersecurity
This Dark Reading Tech Digest gives an in-depth look at the biggest emerging threats and disruptive forces that are changing the face of cybersecurity today.
Flash Poll
The State of IT Operations and Cybersecurity Operations
The State of IT Operations and Cybersecurity Operations
Your enterprise's cyber risk may depend upon the relationship between the IT team and the security team. Heres some insight on what's working and what isn't in the data center.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2019-15129
PUBLISHED: 2019-08-18
The Recruitment module in Humanica Humatrix 7 1.0.0.203 and 1.0.0.681 allows an unauthenticated attacker to access all candidates' files in the photo folder on the website by specifying a "user id" parameter and file name, such as in a recruitment_online/upload/user/[user_id]/photo/[file_n...
CVE-2019-15130
PUBLISHED: 2019-08-18
The Recruitment module in Humanica Humatrix 7 1.0.0.203 and 1.0.0.681 allows an unauthenticated attacker to upload any file type to a candidate's profile picture folder via a crafted recruitment_online/personalData/act_personaltab.cfm multiple-part POST request with a predictable WRC01_USERID parame...
CVE-2019-15135
PUBLISHED: 2019-08-18
The handshake protocol in Object Management Group (OMG) DDS Security 1.1 sends cleartext information about all of the capabilities of a participant (including capabilities inapplicable to the current session), which makes it easier for attackers to discover potentially sensitive reachability informa...
CVE-2019-15136
PUBLISHED: 2019-08-18
The Access Control plugin in eProsima Fast RTPS through 1.9.0 does not check partition permissions from remote participant connections, which can lead to policy bypass for a secure Data Distribution Service (DDS) partition.
CVE-2019-15137
PUBLISHED: 2019-08-18
The Access Control plugin in eProsima Fast RTPS through 1.9.0 allows fnmatch pattern matches with topic name strings (instead of the permission expressions themselves), which can lead to unintended connections between participants in a Data Distribution Service (DDS) network.