时间:2025-06-17 10:03:47 来源:网络整理编辑:娛樂
The past few months have not been good to WhatsApp users. Unfortunately, that doesn't look like it's
The past few months have not been good to WhatsApp users. Unfortunately, that doesn't look like it's about to change any time soon.
The Facebook-owned messaging app acknowledged and patched a major vulnerability that gave hackers the ability to access files on a victim's computer. All you had to do to fall prey to this attack was click a disguised link preview sent via the messaging app. In other words, it would have been an easy mistake for users to make.
Importantly, this did not affect every single WhatsApp user. Rather, a WhatsApp user had to have the iOS version of the messaging app paired to either a PC or MacOS WhatsApp desktop app.
"A vulnerability in WhatsApp Desktop when paired with WhatsApp for iPhone allows cross-site scripting and local file reading," reads the Facebook bug report. "Exploiting the vulnerability requires the victim to click a link preview from a specially crafted text message."
In a Feb. 4 blog post, the security researcher who discovered and disclosed the vulnerability detailed his process and noted that WhatsApp should really get its shit together.
"It is 2020," wrote Gal Weizman, "no product should be allowing a full read from the file system and potentially a [remote code execution] from a single message."
Patrick Wardle, a security researcher at Jamf and founder of Objective-See, told Mashable over Twitter direct message that "often desktop versions of apps aren't as well audited or well written ...and thus often open to attacks."
He added that this specific specific bug "was likely rather trivial to exploit," but cautioned against people freaking out.
"[Still]," wrote Wardle, "a super neat bug, and had the potential to impact lots of users (I use WhatsApp desktop), so definitely happy a security researcher uncovered it and that FB patched it quickly."
We reached out to Facebook in an effort to determine how many people were vulnerable to this exploit and how many, if any, were actually affectedby it. We've received no response as of press time.
Notably, WhatsApp vulnerabilities can have serious consequences. Just this past month, a security firm hired by Amazon CEO Jeff Bezos claimed in a report that the CEO's phone may have been hacked following the receipt of a malicious WhatsApp message. And while Bezos will be fine, people with less power and resources who fall victim to similar attacks may not fare as well.
Facebook is aware of this, but suggests at least some of the blame should lie elsewhere. Following the news of Bezos' hacked phone, the company's vice president of Europe, the Middle East and Africa, Nicola Mendelsohn, suggested to Bloombergthat Apple is the real problem here.
"One of the things that it highlights is actually some of the potential underlying vulnerabilities that exist on the actual operating systems on phones," Mendelsohn told the publication. "From a WhatsApp perspective, from a Facebook perspective, the thing that we care about the most, the thing that we invest in is making sure that the information that people have with us is safe and secure."
SEE ALSO: Mic on Bezos' hacked phone possibly compromised for months
Which, yeah, great. Making sure WhatsApp information is "safe and secure" sounds great, but perhaps that should include not allowing malicious texts that let hackers access victims' computers? Sounds like a good place to start.
Or, if that's too much, maybe Facebook should start recommending Signal.
UPDATE: Feb. 5, 2020, 2:02 p.m. PST:This story has been updated with comment from Patrick Wardle.
TopicsCybersecurityFacebookWhatsApp
WhatsApp announces plans to share user data with Facebook2025-06-17 09:32
艾克森加盟格雷米奧有望下周敲定 將簽約至2022賽季結束2025-06-17 09:31
敗人品?波蘭官推曬梅西扶額圖 將在世界杯戰阿根廷2025-06-17 09:15
曼聯官宣與B費續約 簽到2026年附加一年延長選項2025-06-17 09:15
Is Samsung's Galaxy Note7 really the best phone?2025-06-17 09:07
韓國足協 :巴西隊或在6月與韓國隊熱身 我們正在篩選對手2025-06-17 08:59
世界杯G組賽程:巴西晉級難度不大 首輪戰塞爾維亞2025-06-17 08:28
國足官方:4月3日上午 中國男足將和U23男足一同啟程回國2025-06-17 08:10
Pole vaulter claims his penis is not to blame2025-06-17 08:01
女足美女國門曬易烊千璽簽名照:期待能有真正同框一天2025-06-17 07:56
This company is hiring someone just to drink all day2025-06-17 09:45
世界杯獎金分配:冠軍4200萬美元 參賽即獲1050萬2025-06-17 09:26
申花主帥:球隊還在挽留莫雷諾 有很多人願底薪加盟2025-06-17 09:18
曼聯VS萊斯特城首發 :C羅缺席 朗尼克稱其患了流感2025-06-17 08:53
Here's what 'Game of Thrones' actors get up to between takes2025-06-17 08:48
津媒 :田依濃接近加盟津門虎 5外援配置基本確定2025-06-17 08:13
國足80後時代將就此畫上句號 力不從心難進下一世界杯周期2025-06-17 07:58
曼聯官宣與B費續約 簽到2026年附加一年延長選項2025-06-17 07:37
This coloring book is here for all your relationship goals2025-06-17 07:35
梅西赤身裸體慘遭鎖喉合影 滿臉不情願全程喊不要2025-06-17 07:20