WhatsApp Patches Vulnerability in Image Filter Function That Could Have Led to Data Exposure

WhatsApp brought the patch in February and added two new checks in place to restrict memory access.

Advertisement
By Jagmeet Singh | Updated: 2 September 2021 19:16 IST
Highlights
  • WhatsApp was discovered with a vulnerability in its image filter function
  • Check Point Research reported the issue to WhatsApp in November
  • WhatsApp for Android and WhatsApp Business for Android were impacted

WhatsApp fixed the vulnerability related to its image filter function in version 2.21.1.13

Photo Credit: Reuters

WhatsApp has patched a vulnerability that could allow an attacker to read sensitive information from the app's memory, including private messages using a specially crafted image. The vulnerability was reported to WhatsApp by cybersecurity firm Check Point Research, and it existed within the image filter function of WhatsApp for Android and WhatsApp Business for Android that allows users to add filters to their images. The Facebook-owned company fixed the security issue after it was reported by Check Point researchers and claimed that there was no evidence that the vulnerability was ever abused.

Called “Out-Of-Bounds read-write vulnerability”, the issue was disclosed to WhatsApp by Check Point Research on November 10, 2020. WhatsApp took some time in fixing the bug and issued a patch in February. It was provided to end users through the version 2.21.1.13 of both WhatsApp for Android and WhatsApp Business for Android apps.

Advertisement

Researchers at Check Point Research were able to discover the vulnerability that is technically a memory corruption issue while looking at the way WhatsApp processes and sends images on its platform. During the research, it was found that the image filter function of the messaging app crashes when it was used with some specially-designed GIF files. That brought the researchers to the point from where they were able to spot the loophole.

According to Check Point Research, the vulnerability could be triggered after a user opens an attachment containing a maliciously crafted image file, tries to apply a filter, and then sends the image with the filter applied back to the attacker. The researchers, thus, noted that hackers would have required “complex steps and extensive user interaction” to exploit the issue.

Advertisement

However, if it could be successfully exploited, the vulnerability is claimed to allow hackers to read sensitive information from WhatsApp memory that include private messages and previously shared images and videos.

“Once we discovered the security vulnerability, we quickly reported our findings to WhatsApp, who was cooperative and collaborative in issuing a fix. The result of our collective efforts is a safer WhatsApp for users worldwide,” said Oded Vanunu, Head of Products Vulnerabilities Research at Check Point, in a prepared statement.

Advertisement

WhatsApp has listed the details of the vulnerability on its security advisories site as CVE-2020-1910. The platform added two new checks on source and filter images to restrict memory access.

“People should have no doubt that end-to-end encryption continues to work as intended and people's messages remain safe and secure,” WhatsApp said in its statement given to Check Point Research. “This report involves multiple steps a user would have needed to take and we have no reason to believe users would have been impacted by this bug. That said, even the most complex scenarios researchers identify can help increase security for users.”

Advertisement

WhatsApp also recommended its users to keep their apps and operating systems up to date, download updates whenever they're available, report suspicious messages, and reach out directly to its team if they experience issues using WhatsApp.


Are the Galaxy Z Fold 3 and Z Flip 3 still made for enthusiasts — or are they good enough for everyone? We discussed this on Orbital, the Gadgets 360 podcast. Orbital is available on Apple Podcasts, Google Podcasts, Spotify, Amazon Music and wherever you get your podcasts.
Affiliate links may be automatically generated - see our ethics statement for details.
 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Advertisement

Related Stories

Popular Mobile Brands
  1. CMF Watch 3 Pro India Launch Finally Confirmed, Here's What to Expect
  2. OnePlus Pad 4 Launched in India With Flagship Chip and These Features
  3. These Four Xiaomi Phones Are Now Eligible to Get Android 17 Beta Updates
  4. Motorola Razr 2026 Series With Up to 4-Inch Cover Display Launched
  5. Moto G47 Debuts Globally With a 108-Megapixel Camera at This Price
  6. Moto G87 Launched With 200-Megapixel Main Camera, 5,200mAh Battery
  7. Raakaasa OTT Release Date Confirmed: Know When and Where to Watch it Online
  8. iQOO Z11 Global Variant Visits Geekbench With a Different Snapdragon Chip
  9. Oppo Find X10 Leaks Hint at 165Hz Display, New Periscope Telephoto Camera
  1. iQOO Z11 Global Variant Spotted on Geekbench Database With Snapdragon Chipset, Unlike Chinese Model
  2. Samsung Reportedly Plans to Launch Galaxy Book Models With Android-Based One UI 9 Soon
  3. PS5 Linux Loader Gets Public Release, Allowing Users to Run Steam and PC Games on Console
  4. Nine Crypto Scam Centres Targeting US Users Shut Down in Joint Operation Involving UAE, US and China
  5. Google Photos Unveils New AI-Powered Wardrobe Feature to Help You Decide What to Wear
  6. OpenAI CEO Sam Altman Teases GPT-5.5 Cyber AI Model Rollout, Could Take On Anthropic’s Claude Mythos
  7. Vivo X Fold 6 Leaks Hint at 200-Megapixel Camera, MediaTek Dimensity 9500 Chip and 7,000mAh Battery
  8. Raakaasa OTT Release Date Confirmed: Know When and Where to Watch it Online
  9. Moto G47 Launched With 108-Megapixel Camera, 5,200mAh Battery: Price, Specifications
  10. Sony Issues Statement on New DRM Check for PS5, PS4 Games After Backlash
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.