Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Attacks/Breaches

12/17/2019
05:00 PM
Connect Directly
Twitter
LinkedIn
RSS
E-Mail
50%
50%

Facebook Fixes WhatsApp Group Chat Security Issue

Flaw allowed attackers to repeatedly crash group chat and force users to uninstall and reinstall app, Check Point says.

Facebook has fixed a bug in its WhatsApp chat platform that gave attackers a way to send a malicious group-chat message capable of repeatedly crashing the entire application for all members of a targeted chat group.

To regain access to the application, the victim would have had to uninstall and reinstall WhatsApp. Without re-installation, the user couldn't return to the chat group because the app would repeatedly crash with each attempt.

The targeted group itself would have to be deleted and restarted, resulting in a complete loss of group chat history, Check Point said.

"The crash-loop is a killing of the app that is unstoppable," says Ekram Ahmed, head of public relations at Check Point. "In the first cycle, the app is crashed. Then the user tries to regenerate the app. The app crashes again without any warning. It's a consistent loop that crashes the app - on and on," he says.

This is the second time in recent months that Check Point has identified an issue in WhatsApp. At Black Hat USA this August, researchers from the company showed how an attacker could intercept and manipulate WhatsApp messages in an individual or group setting to spread fake news and create other problems.  

Check Point researchers used a Web-debugging tool to intercept and decrypt the communication that happens between WhatsApp and WhatsApp Web when a user launches the desktop version of the app. By replacing some of the parameters in that communication, the researchers showed how they could change the content of chat messages and impersonate others.

At the time, Facebook described the issue as having nothing to do with the security of the end-to-end encryption on its messaging platform. The company has instead said the issue is similar to someone altering the contents of an email message. More than 500 million people worldwide on average are active on WhatsApp daily, according to Statista.

The latest — and now patched — exploit involves the same communication between the mobile and Web version of WhatsApp. In this case, the researchers found that by examining and manipulating one specific message parameter containing a message sender's phone number, they could cause the app to crash for all members in a chat group.

An attacker would first need to gain access to a target group and assume the identity of a group member, which in this case could be accomplished by manipulating the message parameter containing the user's phone number, Ahmed says. WhatsApp allows for up to 256 members to be part of a single group.

The attacker could then edit other specific message parameters and create a malicious message that is sent to all members in a targeted group, causing the crash-loop.

Check Point reported the issue to WhatsApp's bug bounty program in August and the issue was quickly resolved, the security vendor said. A fix for the flaw is available in WhatsApp version 2.19.58 and users should manually apply it as soon as possible, Check Point advised.

Erich Kron, security awareness advocate at KnowBe4, said that while the bug is destructive and inconvenient, it at least does not enable the content of conversations or personal data to be exposed. Apple Store currently does not have the new fixed version of WhatsApp available for download, he noted, but users should keep checking and apply the patch as soon as it becomes available.

Related Content:

Check out The Edge, Dark Reading's new section for features, threat data, and in-depth perspectives. Today's top story: "Disarming Disinformation"

Jai Vijayan is a seasoned technology reporter with over 20 years of experience in IT trade journalism. He was most recently a Senior Editor at Computerworld, where he covered information security and data privacy issues for the publication. Over the course of his 20-year ... View Full Bio

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Current Issue
6 Emerging Cyber Threats That Enterprises Face in 2020
This Tech Digest gives an in-depth look at six emerging cyber threats that enterprises could face in 2020. Download your copy today!
Flash Poll
State of Cybersecurity Incident Response
State of Cybersecurity Incident Response
Data breaches and regulations have forced organizations to pay closer attention to the security incident response function. However, security leaders may be overestimating their ability to detect and respond to security incidents. Read this report to find out more.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2020-8144
PUBLISHED: 2020-04-01
The UniFi Video Server v3.9.3 and prior (for Windows 7/8/10 x64) web interface Firmware Update functionality, under certain circumstances, does not validate firmware download destinations to ensure they are within the intended destination directory tree. It accepts a request with a URL to firmware u...
CVE-2020-8145
PUBLISHED: 2020-04-01
The UniFi Video Server (Windows) web interface configuration restore functionality at the “backup� and “wizard� endpoints does not implement sufficient privilege checks. Low privileged users, belonging to the PUBLIC_GROUP ...
CVE-2020-8146
PUBLISHED: 2020-04-01
In UniFi Video v3.10.1 (for Windows 7/8/10 x64) there is a Local Privileges Escalation to SYSTEM from arbitrary file deletion and DLL hijack vulnerabilities. The issue was fixed by adjusting the .tsExport folder when the controller is running on Windows and adjusting the SafeDllSearchMode in the win...
CVE-2020-6009
PUBLISHED: 2020-04-01
LearnDash Wordpress plugin version below 3.1.6 is vulnerable to Unauthenticated SQL Injection.
CVE-2020-6096
PUBLISHED: 2020-04-01
An exploitable signed comparison vulnerability exists in the ARMv7 memcpy() implementation of GNU glibc 2.30.9000. Calling memcpy() (on ARMv7 targets that utilize the GNU glibc implementation) with a negative value for the 'num' parameter results in a signed comparison vulnerability. If an attacker ...