WhatsApp flaw allowed spyware injection via calls

By
Follow google news

Pegasus comes calling whether you answer or not.

Facebook-owned WhatsApp has issued urgent patches after the discovery of a vulnerability that allows spyware injection through calls, whether or not victims answer them.

WhatsApp flaw allowed spyware injection via calls

The chat and IP telephony service, with 1.5 billion claimed users worldwide, said that a buffer overflow vulnerability allowed remote code execution via specially crafted secure real-time transport protocol data packets sent to targets' phones. 

Affected versions include:

  • WhatsApp for Android prior to v2.19.134
  • WhatsApp Business for Android prior to v2.19.44
  • WhatsApp for iOS prior to v2.19.51
  • WhatsApp Business for iOS prior to v2.19.51
  • WhatsApp for Windows Phone prior to v2.18.348,
  • WhatsApp for Tizen prior to v2.18.15.

WhatsApp has patched its servers against the vulnerability.

The spyware injected through the vulnerability is believed to be the Pegasus malware, developed by Israeli company NSO Group, according to a report in the Financial Times.

Pegasus runs on Google Android and Apple iOS devices, and can delete call logs, activate the camera and microphone, and access and exfiltrate location information and messages.

A human rights lawyer in London was allegedly hit by a failed attempt to infect a device, FT reported.

The lawyer acted for a Saudi dissident who had sued NSO Group for selling its software to repressive regimes in the Middle East.

Pegasus is also thought to have been used against journalist Jamal Khashoggi, who was murdered at a Saudi-Arabian consulate in Turkey.

Got a news tip for our journalists? Share it with us anonymously here.
Copyright © iTnews.com.au . All rights reserved.
Tags:

Most Read Articles

The BoM has finally tamed SSL

The BoM has finally tamed SSL

Australian chief at US defence contractor L3Harris sold exploits to Russia

Australian chief at US defence contractor L3Harris sold exploits to Russia

Scores of Australian Cisco devices remain BADCANDY infected

Scores of Australian Cisco devices remain BADCANDY infected

Tasmanian gov agencies impacted by cyber attack

Tasmanian gov agencies impacted by cyber attack

Log In

  |  Forgot your password?