WhatsApp Bug Could Have Allowed Hackers to Steal Files, Messages With GIFs: Report

WhatsApp says the bug was fixed last month.

Advertisement
By Gadgets 360 Staff With Inputs From IANS | Updated: 3 October 2019 13:51 IST
Highlights
  • A security bug was reportedly found in WhatsApp
  • The danger stems from a double-free bug in WhatsApp
  • WhatsApp said the bug was fixed last month

A security bug was reportedly found in Facebook-owned instant messenger WhatsApp that could let attackers obtain access to a device and steal data by using a malicious GIF file. The danger stems from a double-free bug in WhatsApp, according to a researcher going by the nickname Awakened, The Next Web reported on Wednesday. WhatsApp said the bug was fixed last month and it had “no reason to believe” that the bug affected anyone.

A double-free vulnerability is a memory corruption anomaly that could crash an application or open up an exploit vector that attackers can abuse to gain access to users' device.

Advertisement

According to Awakened's post on GitHub, the flaw resided in WhatsApp's Gallery view implementation that is used to generate previews for photographs, videos and GIFs.

All it takes to perform the attack is to craft a malicious GIF, and wait for the user to open the WhatsApp gallery, the report added.

Advertisement

"The exploit works well until WhatsApp version 2.19.230. The vulnerability is officially patched in WhatsApp version 2.19.244," wrote the researcher.

The bug also works for Android 8.1 and Android 9.0 OS but does not work for Android 8.0 and below.

Advertisement

In the older Android versions, double-free could still be triggered. However, because of the malloc calls by the system after the double-free, the app just crashes before reaching to the point that we could control the PC register, according to a report in Gizmodo.

“The key point that the [vulnerability disclosure] makes is that this issue affects the user on the sender side, meaning the issue could in theory occur when the user takes action to send a GIF. The issue would impact their own device,” a WhatsApp spokesperson told The Next Web. “It was reported and quickly addressed last month. We have no reason to believe this affected any users though of course we are always working to provide the latest security features to our users.”

 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Further reading: WhatsApp
Advertisement

Related Stories

Popular Mobile Brands
  1. iQOO Z11 Global Variant Visits Geekbench With a Different Snapdragon Chip
  2. Raakaasa OTT Release Date Confirmed: Know When and Where to Watch it Online
  3. Sony Issues Statement on New DRM Check for PS5, PS4 Games After Backlash
  4. Moto G87 Launched With 200-Megapixel Main Camera, 5,200mAh Battery
  5. CMF Watch 3 Pro India Launch Finally Confirmed, Here's What to Expect
  6. House of the Dragon Season 3 OTT Release Date: When and Where to Watch it Online?
  7. How to Prepare Your MacBook for Sale or Trade-In: A Step-by-Step Guide
  8. The iQOO Neo 10 Is Now Available in These New Colour Variants in India
  9. Moto G47 Debuts Globally With a 108-Megapixel Camera at This Price
  1. ULA Atlas V Launches 29 Amazon Kuiper Satellites in Return Mission
  2. Moto Buds 2 Plus Launched in India With Hi-Res Audio, Up to 40 Hours of Total Playback Time: Price, Features
  3. iQOO Z11 Global Variant Spotted on Geekbench Database With Snapdragon Chipset, Unlike Chinese Model
  4. Samsung Reportedly Plans to Launch Galaxy Book Models With Android-Based One UI 9 Soon
  5. PS5 Linux Loader Gets Public Release, Allowing Users to Run Steam and PC Games on Console
  6. Nine Crypto Scam Centres Targeting US Users Shut Down in Joint Operation Involving UAE, US and China
  7. Google Photos Unveils New AI-Powered Wardrobe Feature to Help You Decide What to Wear
  8. OpenAI CEO Sam Altman Teases GPT-5.5 Cyber AI Model Rollout, Could Take On Anthropic’s Claude Mythos
  9. Vivo X Fold 6 Leaks Hint at 200-Megapixel Camera, MediaTek Dimensity 9500 Chip and 7,000mAh Battery
  10. Raakaasa OTT Release Date Confirmed: Know When and Where to Watch it Online
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.