WhatsApp Bug Could Let Attackers Crash the App, Delete Group Messages: Check Point

WhatsApp users who haven’t updated their Android app since the middle of September are advised to install the latest version.

Advertisement
By Jagmeet Singh | Updated: 17 December 2019 19:24 IST
Highlights
  • WhatsApp bug was discovered by Check Point Research in August
  • Users wouldn’t be able to restore their group conversation
  • WhatsApp Web would be used to cause crash loop

WhatsApp rolled out an update in September to fix the bug

WhatsApp has fixed a bug that could have allowed attackers to deliver a malicious group message to repeatedly crash the app for all the members of the group, a report by Check Point Research revealed on Tuesday. The bug, which was discovered in August, is said to have the potential to cause a crash loop that could only be fixed by completely uninstall and reinstall the app. Even after reinstalling, users wouldn't be able to return to the affected group and hence would lose all the messages and media content exchanged in that particular group.

According to the blog post by Check Point Research detailing the bug, an attacker would need to be a member of the target WhatsApp group to impact its other members. The instant messaging app has a limit of 256 members per group, which isn't too small to make room for a bad actor.

Once they have gained membership, the bad actor would need to use WhatsApp Web and debugging tool like Google Chrome's DevTools to edit specific message parameters that cause the crash loop for all group members.

Advertisement

The bug was found by the Check Point Research team after inspecting the communications between WhatsApp and WhatsApp Web. The researchers were able to manipulate the parameters used for WhatsApp communications that could cause repeated crash. Furthermore, technical details of the bug have been published in the blog post.

Advertisement

Although the affected users would be able to fix the crash loop by reinstalling WhatsApp on their devices, the bug forces them to delete the group that removes all its messages and media content.

“Because WhatsApp is one of the world's leading communication channels for consumers, businesses and government agencies, the ability to stop people using WhatsApp and delete valuable information from group chats is a powerful weapon for bad actors,” said Oded Vanunu, Check Point's Head of Product Vulnerability Research, in a media statement.

Advertisement

Check Point Research disclosed its findings to the WhatsApp bug bounty programme on August 28. WhatsApp has fixed the flaw starting its Android version number 2.19.58. Moreover, users, especially those who haven't updated WhatsApp since the middle of September, are recommended to download the latest version to prevent instances of crashes through malicious group messages.

“WhatsApp greatly values the work of the technology community to help us maintain strong security for our users globally,” said WhatsApp Software Engineer Ehren Kret. “Thanks to the responsible submission from Check Point to our bug bounty program, we quickly resolved this issue for all WhatsApp apps in mid-September. We have also recently added new controls to prevent people from being added to unwanted groups to avoid communication with untrusted parties all together.”

Advertisement

The latest fix comes weeks after WhatsApp was found to include an MP4 file security flaw that could be used to trigger remote code execution (RCE) or denial-of-service (DoS) attacks. The Facebook-owned app also in September fixed a bug that could let attackers steal user data directly through a malicious GIF file.

WhatsApp has a strong base of over 1.5 billion users across the globe -- with more than 400 million users in India alone. This gives a significant reason to researchers to actively dig in and find new vulnerabilities.

 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Advertisement

Related Stories

Popular Mobile Brands
  1. iQOO Neo 11 With Snapdragon 8 Elite SoC Launched: Price, Specifications
  2. Top OTT Releases of the Week: Kantara Chapter 1, Lokah Chapter 1, Idli Kadai, and More
  3. Gemini 3 AI Model Will Be Released Soon, Says Google CEO Sundar Pichai
  4. Reliance Offers Free 18-Month Google AI Pro with Gemini, Veo to Jio Users
  5. Realme GT 8 Pro Will Launch in India in November With This Chipset
  6. Vivo X300 Series With 200-Megapixel Zeiss Camera Launched Globally
  7. Samsung Galaxy S26 Series Teased to Launch With These Notable Upgrades
  8. Vivo X300 Series Launching Today: Everything You Need to Know
  9. Lava Agni 4 With Metal Design and Flat Edges Teased Ahead of Debut
  1. Scientists May Have Finally Solved the Sun’s Mysteriously Hot Atmosphere Puzzle
  2. Vivo X300 Series Launched Globally With 200-Megapixel Zeiss Camera, Up to 6.78-Inch Display: Price, Features
  3. Canva Introduces Revamped Video Editor, New AI Tools and a Marketing Platform
  4. Thode Door Thode Paas OTT Release Date: Know When and Where to Watch it Online
  5. Blackmail Now Streaming Online: Know Where to Watch This Tamil Crime Thriller Movie
  6. Eva Husson’s Playdate OTT Release Date: When and Where to Watch it Online?
  7. Raj Tarun's Chiranjeeva OTT Release Date: When and Where to Watch it Online?
  8. Bitchat Becomes Jamaica’s Go-to App as Hurricane Melissa Cripples Communication
  9. Google Maps Is Reportedly Developing a New Power Saving Mode for Navigation
  10. Take-Two CEO Says AI Won't Be 'Very Good' at Making a Game Like Grand Theft Auto
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.