时间:2025-05-01 12:02:41 来源:网络整理编辑:熱點
The past few months have not been good to WhatsApp users. Unfortunately, that doesn't look like it's
The past few months have not been good to WhatsApp users. Unfortunately, that doesn't look like it's about to change any time soon.
The Facebook-owned messaging app acknowledged and patched a major vulnerability that gave hackers the ability to access files on a victim's computer. All you had to do to fall prey to this attack was click a disguised link preview sent via the messaging app. In other words, it would have been an easy mistake for users to make.
Importantly, this did not affect every single WhatsApp user. Rather, a WhatsApp user had to have the iOS version of the messaging app paired to either a PC or MacOS WhatsApp desktop app.
"A vulnerability in WhatsApp Desktop when paired with WhatsApp for iPhone allows cross-site scripting and local file reading," reads the Facebook bug report. "Exploiting the vulnerability requires the victim to click a link preview from a specially crafted text message."
In a Feb. 4 blog post, the security researcher who discovered and disclosed the vulnerability detailed his process and noted that WhatsApp should really get its shit together.
"It is 2020," wrote Gal Weizman, "no product should be allowing a full read from the file system and potentially a [remote code execution] from a single message."
Patrick Wardle, a security researcher at Jamf and founder of Objective-See, told Mashable over Twitter direct message that "often desktop versions of apps aren't as well audited or well written ...and thus often open to attacks."
He added that this specific specific bug "was likely rather trivial to exploit," but cautioned against people freaking out.
"[Still]," wrote Wardle, "a super neat bug, and had the potential to impact lots of users (I use WhatsApp desktop), so definitely happy a security researcher uncovered it and that FB patched it quickly."
We reached out to Facebook in an effort to determine how many people were vulnerable to this exploit and how many, if any, were actually affectedby it. We've received no response as of press time.
Notably, WhatsApp vulnerabilities can have serious consequences. Just this past month, a security firm hired by Amazon CEO Jeff Bezos claimed in a report that the CEO's phone may have been hacked following the receipt of a malicious WhatsApp message. And while Bezos will be fine, people with less power and resources who fall victim to similar attacks may not fare as well.
Facebook is aware of this, but suggests at least some of the blame should lie elsewhere. Following the news of Bezos' hacked phone, the company's vice president of Europe, the Middle East and Africa, Nicola Mendelsohn, suggested to Bloombergthat Apple is the real problem here.
"One of the things that it highlights is actually some of the potential underlying vulnerabilities that exist on the actual operating systems on phones," Mendelsohn told the publication. "From a WhatsApp perspective, from a Facebook perspective, the thing that we care about the most, the thing that we invest in is making sure that the information that people have with us is safe and secure."
SEE ALSO: Mic on Bezos' hacked phone possibly compromised for months
Which, yeah, great. Making sure WhatsApp information is "safe and secure" sounds great, but perhaps that should include not allowing malicious texts that let hackers access victims' computers? Sounds like a good place to start.
Or, if that's too much, maybe Facebook should start recommending Signal.
UPDATE: Feb. 5, 2020, 2:02 p.m. PST:This story has been updated with comment from Patrick Wardle.
TopicsCybersecurityFacebookWhatsApp
Fake news reports from the Newseum are infinitely better than actual news2025-05-01 11:40
下賽季歐冠32強已確定24席 英超法甲各剩一隊待定2025-05-01 11:26
巴黎真核:當我看到說姆巴佩在馬德裏 這讓我惡心2025-05-01 11:19
青島名宿崔肖佳舉報山東省足管中心領導侵吞全運女足獎金2025-05-01 10:22
WhatsApp announces plans to share user data with Facebook2025-05-01 10:17
韓喬生:中超花了兩個月找比賽場地 最後幾個月完成一年的賽程2025-05-01 10:17
謝林漢姆勸凱恩:與曼聯相比 熱刺更容易贏得獎杯2025-05-01 10:14
英超冠軍懸念最後一輪揭曉 傑隊當判官拯救利物浦?2025-05-01 10:09
Tourist survives for month in frozen New Zealand wilderness after partner dies2025-05-01 09:37
尤文3年合同+750萬歐年薪報價博格巴 球員方麵正評估2025-05-01 09:26
This app is giving streaming TV news a second try2025-05-01 12:00
邵佳一:劉邵子洋學習能力強 、性格好 前途不可限量2025-05-01 11:42
於根偉:保持清醒頭腦 保級依然是天津隊新賽季首要目標2025-05-01 10:49
歐戰積分平皇馬追紅軍 新科歐聯冠軍:你好,歐冠2025-05-01 10:49
One of the most controversial power struggles in media comes to a close2025-05-01 10:41
德轉 :2022中超共報名599名球員 廣州平均年齡20.7歲最年輕2025-05-01 09:57
足協杯整體後移確保中超完賽 或在世界杯期間進行2025-05-01 09:51
中超遭遇“斷奶”危機 有俱樂部晚去賽區隻為省錢2025-05-01 09:41
17 questions you can answer if you're a good communicator2025-05-01 09:39
曝梅西將收購邁阿密國際35%股份 2023年赴大聯盟2025-05-01 09:34