WhatsApp, Telegram patch flaws after CheckPoint reveals vulnerabilities

WhatsApp and Telegram scramble to patch up a security flaw after it was revealed by Check Point how a vulnerability could expose users to security risk on various chat applications with end-to-end encryption.

The vulnerability was published on the Check Point blog, with video demos showing attackers taking over control of a user account through sending a malicious file or a video. The security researchers found that both WhatsApp and Telegram processes and encrypts certain types of file without validating if any malicious code is present. This means that while WhatsApp and Telegram do not know the content of the files – attackers could send malicious codes through.

In the video it was demonstrated that files could be masked as pictures or videos, and once opened, attackers can gain access to local storage as well as access user’s account.

 

In WhatsApp’s case, just by viewing the page, without clicking on anything, the victim’s local storage data will be sent to the attacker, allowing them to take over his/her account. However, since WhatsApp web does not allow a client to have more than one active session at a time so after the attacker steal the victim account the victim will receive a notification.

In the case of Telegram, it requires a specific step, where users view a video in a new tab. However, the user won’t be made aware of the account takeover since Telegram allows users to keep as many active sessions as they want at the same time.

As of now, there has been no reports of similar attacks actually used in the wild against either company’s products. Both WhatsApp and Telegram have bee notified and a patch has been made with the latest update.

Comment what you think!