时间:2026-05-01 13:22:58 来源:网络整理编辑:焦點
The past few months have not been good to WhatsApp users. Unfortunately, that doesn't look like it's
The past few months have not been good to WhatsApp users. Unfortunately, that doesn't look like it's about to change any time soon.
The Facebook-owned messaging app acknowledged and patched a major vulnerability that gave hackers the ability to access files on a victim's computer. All you had to do to fall prey to this attack was click a disguised link preview sent via the messaging app. In other words, it would have been an easy mistake for users to make.
Importantly, this did not affect every single WhatsApp user. Rather, a WhatsApp user had to have the iOS version of the messaging app paired to either a PC or MacOS WhatsApp desktop app.
"A vulnerability in WhatsApp Desktop when paired with WhatsApp for iPhone allows cross-site scripting and local file reading," reads the Facebook bug report. "Exploiting the vulnerability requires the victim to click a link preview from a specially crafted text message."

In a Feb. 4 blog post, the security researcher who discovered and disclosed the vulnerability detailed his process and noted that WhatsApp should really get its shit together.
"It is 2020," wrote Gal Weizman, "no product should be allowing a full read from the file system and potentially a [remote code execution] from a single message."
Patrick Wardle, a security researcher at Jamf and founder of Objective-See, told Mashable over Twitter direct message that "often desktop versions of apps aren't as well audited or well written ...and thus often open to attacks."
He added that this specific specific bug "was likely rather trivial to exploit," but cautioned against people freaking out.
"[Still]," wrote Wardle, "a super neat bug, and had the potential to impact lots of users (I use WhatsApp desktop), so definitely happy a security researcher uncovered it and that FB patched it quickly."
We reached out to Facebook in an effort to determine how many people were vulnerable to this exploit and how many, if any, were actually affectedby it. We've received no response as of press time.
Notably, WhatsApp vulnerabilities can have serious consequences. Just this past month, a security firm hired by Amazon CEO Jeff Bezos claimed in a report that the CEO's phone may have been hacked following the receipt of a malicious WhatsApp message. And while Bezos will be fine, people with less power and resources who fall victim to similar attacks may not fare as well.
Facebook is aware of this, but suggests at least some of the blame should lie elsewhere. Following the news of Bezos' hacked phone, the company's vice president of Europe, the Middle East and Africa, Nicola Mendelsohn, suggested to Bloombergthat Apple is the real problem here.
"One of the things that it highlights is actually some of the potential underlying vulnerabilities that exist on the actual operating systems on phones," Mendelsohn told the publication. "From a WhatsApp perspective, from a Facebook perspective, the thing that we care about the most, the thing that we invest in is making sure that the information that people have with us is safe and secure."
SEE ALSO: Mic on Bezos' hacked phone possibly compromised for months
Which, yeah, great. Making sure WhatsApp information is "safe and secure" sounds great, but perhaps that should include not allowing malicious texts that let hackers access victims' computers? Sounds like a good place to start.
Or, if that's too much, maybe Facebook should start recommending Signal.
UPDATE: Feb. 5, 2020, 2:02 p.m. PST:This story has been updated with comment from Patrick Wardle.
TopicsCybersecurityFacebookWhatsApp
PlayStation Now game streaming is coming to PC2026-05-01 12:55
洛國富阿蘭體能已不存在問題 李鐵開始重視中場防守2026-05-01 12:51
國足教練組有意補充後防人員入隊 韋世豪王上源等人離隊2026-05-01 12:42
兩級分化 !米蘭聯賽強勢歐冠羸弱 四輪僅獲1個積分2026-05-01 12:42
Fyvush Finkel, Emmy winner for 'Picket Fences,' dies at 932026-05-01 12:09
國足熱身遭中甲隊壓製 或帶25名球員前往阿聯酋2026-05-01 12:05
申花慘敗激怒球迷會:暫停現場助威 直到球隊重大改變為止2026-05-01 11:57
海港小將劉祝潤打破武磊紀錄 成海港最年輕德比進球球員2026-05-01 11:32
There's a big piece of fake chicken stuck to this phone case2026-05-01 11:11
足協杯上海德比異常火爆 海港掌握晉級絕對主動權2026-05-01 10:45
There's a big piece of fake chicken stuck to this phone case2026-05-01 13:22
曝巴薩本有望拿到6000萬歐讚助 因梅西離開而泡湯2026-05-01 13:16
奧斯卡染紅擔心遭追罰 海港賽後第一時間搜集材料申訴2026-05-01 12:50
國足通過熱身賽確定國腳人選 部分球員本周離隊2026-05-01 12:09
Pole vaulter claims his penis is not to blame2026-05-01 11:55
孔蒂談熱刺首秀 :一場瘋狂的比賽 不滿意兩個丟球2026-05-01 11:31
國米雙殺歐冠“大黑馬”創紀錄 出線在望盼雪前恥2026-05-01 11:14
申花零丟球防線一戰崩塌 海港基本鎖定決賽席位2026-05-01 11:12
U.S. government issues warning on McDonald's recalled wearable devices2026-05-01 10:58
奧斯卡回應紅牌 :本意是保護隊友 很明顯對方想搞事情2026-05-01 10:47