{"id":328133,"date":"2019-11-18T17:03:30","date_gmt":"2019-11-18T15:03:30","guid":{"rendered":"https:\/\/mybroadband.co.za\/news\/?p=328133"},"modified":"2019-11-18T17:05:01","modified_gmt":"2019-11-18T15:05:01","slug":"new-whatsapp-video-security-flaw","status":"publish","type":"post","link":"https:\/\/mybroadband.co.za\/news\/security\/328133-new-whatsapp-video-security-flaw.html","title":{"rendered":"New WhatsApp video security flaw"},"content":{"rendered":"<p>A new WhatsApp security vulnerability leaves users&#8217; files and messages exposed to access from attackers.<\/p>\n<p>Facebook issued a<a href=\"https:\/\/web.facebook.com\/security\/advisories\/cve-2019-11931?_rdc=1&amp;_rdr\" target=\"_blank\" rel=\"noopener noreferrer\"><strong> security advisory<\/strong><\/a> last week which warned WhatsApp Messenger users that a modified MP4 video file could be used to initiate remote code execution (RCE) and denial of service (DoS) attacks.<\/p>\n<p>\u201cA stack-based buffer overflow could be triggered in WhatsApp by sending a specially crafted MP4 file to a WhatsApp user,&#8221; the advisory stated.<\/p>\n<p>The susceptibility could make it possible for malicious actors to gain access to messages and files stored on a compromised device.<\/p>\n<p>Both the consumer versions of the Android and iOS app, as well as the Enterprise and Business editions have been affected.<\/p>\n<p>Facebook said that Android versions prior to 2.19.274 and iOS versions older than 2.19.100 are vulnerable.<\/p>\n<h3 class=\"my-4\">Latest updates fix the issue<\/h3>\n<p>WhatsApp has rolled out a patch for the vulnerability, meaning that more recent versions than those mentioned above, should be safe from attack.<\/p>\n<p>Users who are running older versions of WhatsApp are encouraged to update their app.<\/p>\n<p>According to <a href=\"https:\/\/news.softpedia.com\/news\/whatsapp-resolves-critical-mp4-security-vulnerability-exposing-messages-528195.shtml\" target=\"_blank\" rel=\"noopener noreferrer\"><strong>Softpedia<\/strong><\/a>, there appear to be no reported cases of exploits of the flaw at this time.<\/p>\n<p>News of this vulnerability follows the discovery of a previous exploit in WhatsApp&#8217;s Calling feature, which made it possible to install malware on a targeted device, giving hackers total control of the victim&#8217;s smartphone.<\/p>\n<p>At the end of last month, WhatsApp <a href=\"https:\/\/mybroadband.co.za\/news\/security\/325567-whatsapp-files-lawsuit-over-spyware-exploit.html\" target=\"_blank\" rel=\"noopener noreferrer\"><strong>announced<\/strong><\/a> it was suing Israeli-based cyber intelligence organisation NSO Group for its suspected involvement in the development of this malware.<\/p>\n<h3 class=\"my-4\">Now read: <a href=\"https:\/\/mybroadband.co.za\/news\/security\/328053-pre-installed-android-apps-pose-a-big-security-threat-study.html\" rel=\"bookmark\">Pre-installed Android apps pose a big security threat \u2013 Study<\/a><\/h3>\n","protected":false},"excerpt":{"rendered":"<p>A new WhatsApp security vulnerability leaves users&#8217; files and messages exposed to access from attackers.<\/p>\n","protected":false},"author":23,"featured_media":164658,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_sma_x_autopost_status":"idle","_sma_x_autopost_error":"","_sma_x_post_id":"","_sma_facebook_post_id":"","_sma_instagram_post_id":"","_sma_threads_post_id":"","_sma_x_attempts":0,"footnotes":""},"categories":[27],"tags":[161,463,2594],"class_list":["post-328133","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-security","tag-facebook","tag-security-2","tag-whatsapp"],"_links":{"self":[{"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/posts\/328133"}],"collection":[{"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/users\/23"}],"replies":[{"embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/comments?post=328133"}],"version-history":[{"count":2,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/posts\/328133\/revisions"}],"predecessor-version":[{"id":328141,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/posts\/328133\/revisions\/328141"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/media\/164658"}],"wp:attachment":[{"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/media?parent=328133"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/categories?post=328133"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/tags?post=328133"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}