WhatsApp Bug Could Let Attackers Crash the App, Delete Group Messages: Check Point

WhatsApp users who haven’t updated their Android app since the middle of September are advised to install the latest version.

Advertisement
By Jagmeet Singh | Updated: 17 December 2019 19:24 IST
Highlights
  • WhatsApp bug was discovered by Check Point Research in August
  • Users wouldn’t be able to restore their group conversation
  • WhatsApp Web would be used to cause crash loop

WhatsApp rolled out an update in September to fix the bug

WhatsApp has fixed a bug that could have allowed attackers to deliver a malicious group message to repeatedly crash the app for all the members of the group, a report by Check Point Research revealed on Tuesday. The bug, which was discovered in August, is said to have the potential to cause a crash loop that could only be fixed by completely uninstall and reinstall the app. Even after reinstalling, users wouldn't be able to return to the affected group and hence would lose all the messages and media content exchanged in that particular group.

According to the blog post by Check Point Research detailing the bug, an attacker would need to be a member of the target WhatsApp group to impact its other members. The instant messaging app has a limit of 256 members per group, which isn't too small to make room for a bad actor.

Once they have gained membership, the bad actor would need to use WhatsApp Web and debugging tool like Google Chrome's DevTools to edit specific message parameters that cause the crash loop for all group members.

Advertisement

The bug was found by the Check Point Research team after inspecting the communications between WhatsApp and WhatsApp Web. The researchers were able to manipulate the parameters used for WhatsApp communications that could cause repeated crash. Furthermore, technical details of the bug have been published in the blog post.

Advertisement

Although the affected users would be able to fix the crash loop by reinstalling WhatsApp on their devices, the bug forces them to delete the group that removes all its messages and media content.

“Because WhatsApp is one of the world's leading communication channels for consumers, businesses and government agencies, the ability to stop people using WhatsApp and delete valuable information from group chats is a powerful weapon for bad actors,” said Oded Vanunu, Check Point's Head of Product Vulnerability Research, in a media statement.

Advertisement

Check Point Research disclosed its findings to the WhatsApp bug bounty programme on August 28. WhatsApp has fixed the flaw starting its Android version number 2.19.58. Moreover, users, especially those who haven't updated WhatsApp since the middle of September, are recommended to download the latest version to prevent instances of crashes through malicious group messages.

“WhatsApp greatly values the work of the technology community to help us maintain strong security for our users globally,” said WhatsApp Software Engineer Ehren Kret. “Thanks to the responsible submission from Check Point to our bug bounty program, we quickly resolved this issue for all WhatsApp apps in mid-September. We have also recently added new controls to prevent people from being added to unwanted groups to avoid communication with untrusted parties all together.”

Advertisement

The latest fix comes weeks after WhatsApp was found to include an MP4 file security flaw that could be used to trigger remote code execution (RCE) or denial-of-service (DoS) attacks. The Facebook-owned app also in September fixed a bug that could let attackers steal user data directly through a malicious GIF file.

WhatsApp has a strong base of over 1.5 billion users across the globe -- with more than 400 million users in India alone. This gives a significant reason to researchers to actively dig in and find new vulnerabilities.

 

For the latest tech news and reviews, follow Gadgets 360 on X, Facebook, WhatsApp, Threads and Google News. For the latest videos on gadgets and tech, subscribe to our YouTube channel. If you want to know everything about top influencers, follow our in-house Who'sThat360 on Instagram and YouTube.

Advertisement

Related Stories

Popular Mobile Brands
  1. Realme 15T With 50-Megapixel Selfie Camera Debuts in India: See Price
  2. Amazon Great Indian Festival Sale: Deals on Smartphones, Laptops Teased
  1. BCCI Says Crypto, Real Money Gaming Platforms Can’t Bid for Team India’s Title Sponsorship
  2. Scientists Discover Hidden Mantle Layer Beneath the Himalayas Challenging Century-Old Theory
  3. Astronomers Propose Rectangular Telescope to Hunt Earth-Like Planets
  4. Microsoft Testing Native Clipboard Sync Feature to Share Text Between Windows PCs, Android Devices
  5. Su From So OTT Release: When and Where to Watch This Kannada-Language Horror-Comedy Online
  6. Sennheiser Momentum 4 Wireless 80th Anniversary Edition Launched in India With Up to 60 Hour Battery Life
  7. Call of Duty Film Adaption Said to Be a 'Priority' at Paramount, Negotiations on to Acquire Rights
  8. Cannibal Solar Storm May Trigger Auroras as Powerful Geomagnetic Storm to Hit Earth Soon
  9. Apple's iPhone 8 Plus Listed as Vintage Product Ahead of iPhone 17 Launch, 11-Inch MacBook Air Now Obsolete
  10. Hidden Reason Behind Portugal’s Deadly Earthquakes Finally Explained
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.