时间:2026-02-22 04:18:22 来源:网络整理编辑:時尚
The past few months have not been good to WhatsApp users. Unfortunately, that doesn't look like it's
The past few months have not been good to WhatsApp users. Unfortunately, that doesn't look like it's about to change any time soon.
The Facebook-owned messaging app acknowledged and patched a major vulnerability that gave hackers the ability to access files on a victim's computer. All you had to do to fall prey to this attack was click a disguised link preview sent via the messaging app. In other words, it would have been an easy mistake for users to make.
Importantly, this did not affect every single WhatsApp user. Rather, a WhatsApp user had to have the iOS version of the messaging app paired to either a PC or MacOS WhatsApp desktop app.
"A vulnerability in WhatsApp Desktop when paired with WhatsApp for iPhone allows cross-site scripting and local file reading," reads the Facebook bug report. "Exploiting the vulnerability requires the victim to click a link preview from a specially crafted text message."

In a Feb. 4 blog post, the security researcher who discovered and disclosed the vulnerability detailed his process and noted that WhatsApp should really get its shit together.
"It is 2020," wrote Gal Weizman, "no product should be allowing a full read from the file system and potentially a [remote code execution] from a single message."
Patrick Wardle, a security researcher at Jamf and founder of Objective-See, told Mashable over Twitter direct message that "often desktop versions of apps aren't as well audited or well written ...and thus often open to attacks."
He added that this specific specific bug "was likely rather trivial to exploit," but cautioned against people freaking out.
"[Still]," wrote Wardle, "a super neat bug, and had the potential to impact lots of users (I use WhatsApp desktop), so definitely happy a security researcher uncovered it and that FB patched it quickly."
We reached out to Facebook in an effort to determine how many people were vulnerable to this exploit and how many, if any, were actually affectedby it. We've received no response as of press time.
Notably, WhatsApp vulnerabilities can have serious consequences. Just this past month, a security firm hired by Amazon CEO Jeff Bezos claimed in a report that the CEO's phone may have been hacked following the receipt of a malicious WhatsApp message. And while Bezos will be fine, people with less power and resources who fall victim to similar attacks may not fare as well.
Facebook is aware of this, but suggests at least some of the blame should lie elsewhere. Following the news of Bezos' hacked phone, the company's vice president of Europe, the Middle East and Africa, Nicola Mendelsohn, suggested to Bloombergthat Apple is the real problem here.
"One of the things that it highlights is actually some of the potential underlying vulnerabilities that exist on the actual operating systems on phones," Mendelsohn told the publication. "From a WhatsApp perspective, from a Facebook perspective, the thing that we care about the most, the thing that we invest in is making sure that the information that people have with us is safe and secure."
SEE ALSO: Mic on Bezos' hacked phone possibly compromised for months
Which, yeah, great. Making sure WhatsApp information is "safe and secure" sounds great, but perhaps that should include not allowing malicious texts that let hackers access victims' computers? Sounds like a good place to start.
Or, if that's too much, maybe Facebook should start recommending Signal.
UPDATE: Feb. 5, 2020, 2:02 p.m. PST:This story has been updated with comment from Patrick Wardle.
TopicsCybersecurityFacebookWhatsApp
Watch MTV's Video Music Awards 2016 livestream2026-02-22 04:07
尤文噩耗 !基耶利尼傷勢超預期 恐休四周缺席歐冠2026-02-22 03:57
中國女足駐地受到球迷英雄般歡迎 休整後將開啟亞運會備戰2026-02-22 03:48
支付寶公布中國女足奪冠獎金1300萬:球員1000萬 教練300萬2026-02-22 03:23
5 people Tim Cook calls for advice on running the biggest company in the world2026-02-22 03:13
男足集體發文祝賀女足奪冠 武磊 :由衷的敬佩和欽佩2026-02-22 03:03
李佳悅:犧牲小我才能完成大我 熱度退去盼更多人關注女足2026-02-22 02:48
專家:國足補充名單僅2人有A級出場 身價均高於不少國腳2026-02-22 02:32
Watch MTV's Video Music Awards 2016 livestream2026-02-22 02:31
深度:連續三戰逆轉封神 水慶霞到底給女足施了什麽魔法?2026-02-22 01:54
Plane makes emergency landing after engine rips apart during flight2026-02-22 04:15
水慶霞神換人助女足登頂 無孫雯力挺恐被足協放棄2026-02-22 04:13
女足奪冠帶給國人的兩關鍵詞 :實幹業務 拚搏不止2026-02-22 03:37
李佳悅:犧牲小我才能完成大我 熱度退去盼更多人關注女足2026-02-22 03:18
Photos show the Blue Cut fire blazing a path of destruction in California2026-02-22 03:10
尤文前瞻 :弗拉霍維奇紮卡裏亞首秀? 迪巴拉破荒2026-02-22 02:58
深度:連續三戰逆轉封神 水慶霞到底給女足施了什麽魔法?2026-02-22 02:48
女足奪冠影響力空前 多家讚助商蜂擁而至詢問讚助事宜2026-02-22 02:47
Olympics official on Rio's green diving pool: 'Chemistry is not an exact science'2026-02-22 02:08
禁區外4球 !阿森西奧西甲第一 賽季6球平個人最佳2026-02-22 01:58