WhatsApp Bug Could Have Allowed Attackers to Remotely Access Files on Your Desktop

The WhatsApp vulnerability has been tracked as CVE-2019-18426.

Advertisement
By Jagmeet Singh | Updated: 5 February 2020 11:17 IST
Highlights
  • WhatsApp desktop application vulnerability is classed as “high”
  • It impacted WhatsApp Web client to some extent as well
  • WhatsApp users are recommended to install the latest desktop version

WhatsApp desktop application versions prior to 0.3.9309 are affected by the newly reported vulnerability

WhatsApp has been discovered to have a critical vulnerability that could have allowed attackers to remotely access files from a Windows or Mac computer. The vulnerability, which has been fixed by Facebook, could be exploited using the WhatsApp desktop application. It was a mix of multiple high-severity flaws that existed within the WhatsApp desktop application. Some of those flaws were also a part of the WhatsApp Web client that works on Web browsers. The vulnerability essentially allowed for cross-site scripting (XSS) that could be used by remote attackers.

PerimeterX researcher Gal Weizman discovered the WhatsApp vulnerability that has been tracked as CVE-2019-18426. The researcher stated that the security loophole existed within the Content Security Policy (CSP) of WhatsApp that allowed for XSS attacks on the desktop app. The flaw in the CSP also impacted the WhatsApp Web client to some extent as it provided space to alter rich preview banners with malicious content.

The researcher in a blog post mentioned that the Web client was vulnerable to an open-redirect flaw that could have led to persistent cross-site scripting attacks triggered by sending specially crafted messages to WhatsApp users.

Advertisement

However, the scope of the loophole is found to be quite wider on the WhatsApp desktop application over what was discovered on its Web client. The researcher found that he was able to read the file system and identify the remote code execution (RCE) potential on the desktop application. The only thing that the affected WhatsApp users had to do was to click on the specially crafted message to provide backdoor access to attackers.

Advertisement

"For some reason, the CSP rules were not an issue with the Electron based app, so fetching an external payload using a simple JavaScript resource worked," Weizman explained in the blog post.

The researcher demonstrated an attack that could take place using the vulnerability by showing a screenshot highlighting the content of the hosts file fetched from a victim's computer remotely using the WhatsApp desktop application.

Advertisement

WhatsApp vulnerability on its desktop has been demonstrated
Photo Credit: PerimeterX

Advertisement

 

Facebook patched the vulnerability upon receiving an alert from Weizman last year. Moreover, the vulnerability is classed as “high”.

"A vulnerability in WhatsApp Desktop versions prior to 0.3.9309 when paired with WhatsApp for iPhone versions prior to 2.20.10 allows cross-site scripting and local file reading. Exploiting the vulnerability requires the victim to click a link preview from a specially crafted text message," reads the description of the WhatsApp vulnerability provided in the US National Vulnerability Data (NVD).

Late last month, the NVD site revealed that WhatsApp disclosed as many as 12 vulnerabilities in 2019, including seven “critical” ones. The number of vulnerabilities disclosed was significantly higher than the one or two security flaws the instant messaging app reported in the past few years.

 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Advertisement

Related Stories

Popular Mobile Brands
  1. Xiaomi 17 Ultra to Launch in a 'Starry' Green Shade in China on This Date
  2. Oppo Reno 15 Series 5G Confirmed to Launch in India Soon
  3. Oppo Find X9 Ultra Camera Specifications Leaked Ahead of China Launch
  4. Poco M8 Series India Launch Teased, Poco M8 and M8 Pro Could Debut
  5. iQOO Z11 Turbo Design Teased; Specifications Leaked
  6. OnePlus Turbo Visits Geekbench With This Snapdragon Chipset
  7. Ram Pothineni's Andhra King Taluka Premieres on Netflix This December
  1. Oppo Find X9 Ultra Camera Specifications Leak Ahead of Launch; May Feature 200-Megapixel Main, Telephoto Sensors
  2. OnePlus Turbo Reportedly Listed on Geekbench With Snapdragon 8s Gen 4 SoC: Expected Specifications, Features
  3. iQOO Z11 Turbo Design Teased; Could Launch With 6.59-Inch Display, Snapdragon 8 Gen 5 SoC
  4. Poco M8 Series India Launch Teased; Poco M8 and M8 Pro Expected to Debut
  5. Oppo Reno 15 Series 5G Confirmed to Launch in India Soon; Four Models Tipped to Debut
  6. Xiaomi 17 Ultra China Launch Date Announced; Design and ‘Starry’ Green Colourway Revealed
  7. Curiosity Explores Polygon-Covered Rocks in Monte Grande Hollow During Sols 4743-4749
  8. Betelgeuse and the Crab Nebula Reveal Stellar Death and Rebirth in Multi-Telescope Views
  9. Hubble Captures Gas Escaping Sideways Spiral Galaxy NGC 4388 in Virgo Cluster
  10. NASA’s PUNCH Watches Comet Lemmon Respond to the Sun’s Powerful Influence
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.