WhatsApp Reports 6 Previously Undisclosed Vulnerabilities on New Security Site

Of the six new vulnerabilities fixed by WhatsApp, four existed in WhatsApp for Android, with two being a part of its iPhone client.

Advertisement
By Jagmeet Singh | Updated: 4 September 2020 13:13 IST
Highlights
  • WhatsApp has created its new site to list all flaws under one roof
  • The messaging app has been in focus of hackers for quite some time
  • Facebook also announced its third-party vulnerability disclosure policy

WhatsApp has created its security advisory site to be more transparent towards fixing security issues

WhatsApp has revealed six new vulnerabilities that were previously undisclosed and have now been fixed. The Facebook-owned company reported the vulnerabilities on its newly created security advisory webpage that will serve as a single destination to highlight all the security issues spotted and fixed on WhatsApp and reveal associated Common Vulnerabilities and Exposures (CVE). The new development by WhatsApp is aimed to help the technology community benefit from its latest security updates and be more transparent towards notifying users about the flaws and vulnerabilities fixed on the platform.

Of the six new vulnerabilities fixed by WhatsApp, four existed in WhatsApp for Android, with two being a part of its iPhone client, while the remaining two were specifically related to WhatsApp Desktop versions prior to v0.3.4932, as reported on the security advisory site. Two third of the new vulnerabilities were found internally — through code review or automated dynamic analysis — and one third were reported through the bug bounty programme conducted by Facebook.

WhatsApp will be able to continue the practice of revealing vulnerabilities through its newly created security advisory site. This will detail the security issues that the company isn't able to mention in the app release notes of the updates due to the policies and practices of app stores.

Advertisement

The growing presence of WhatsApp that already has over 200 crore users globally has brought it in the focus of hackers around the world. In some past instances, bad actors were able to exploit the app to manipulate messages of users and even snoop their phones. The WhatsApp team itself reported a dozen of security vulnerabilities that were fixed last year, as per the entries listed on the US National Vulnerability Database (NVD).

Advertisement

Thus, it makes sense for WhatsApp to have a dedicated security advisory site where it can list all the security issues under one roof. The arrival of the new site also suggests that the security team behind the world's most popular messaging app could focus more on identifying and patching flaws to resist past issues.

“We are very committed to transparency and this resource is intended to help the broader technology community benefit from the latest advances in our security efforts,” WhatsApp wrote on its security advisory site.

Advertisement

In addition to the new site, WhatsApp parent Facebook has announced its vulnerability disclosure policy that will allow the social media giant to publicly disclose the vulnerabilities it found in a third-party code after 21 days of its reporting.

“Facebook will contact the appropriate responsible party and inform them as quickly as reasonably possible of a security vulnerability we've found. We expect the third party to respond within 21 days to let us know how the issue is being mitigated to protect the impacted people. If we don't hear back within 21 days after reporting, Facebook reserves the right to disclose the vulnerability,” the company said in its advisory related to the new policy.

Advertisement

Companies including Google and Microsoft already have a similar mechanism in place for some time through which they report and disclose vulnerability in third-party offerings.


In 2020, will WhatsApp get the killer feature that every Indian is waiting for? We discussed this on Orbital, our weekly technology podcast, which you can subscribe to via Apple Podcasts or RSS, download the episode, or just hit the play button below.

 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Further reading: WhatsApp security, WhatsApp, Facebook
Advertisement

Related Stories

Popular Mobile Brands
  1. Motorola Edge 70 Launched With Snapdragon 7 Gen 4 SoC, Slim 5.99mm Profile
  2. Moto G67 Power 5G Launched in India With 7,000mAh Battery: See Price
  3. Apple's Low-Cost MacBook Launch Timeline, Price Leaked Ahead of Debut
  4. Samsung Galaxy S26 Ultra Spotted in Leaked Renders With Rounder Corners
  5. Lava Agni 4 Price Range, Features Leaked; Will Launch in These Colourways
  6. Moto G Play (2026), Moto G (2026) With Dimensity 6300 SoC Launched
  7. Realme UI 7.0 Launched With Light Glass Design, AI Features
  8. WhatsApp's Apple Watch App Is Finally Out: Check Features, Compatibility
  9. OnePlus Ace 6 Pro Max Configurations Leaked; May Feature Up to 16GB of RAM
  10. Apple's iOS 26.2 Developer Beta Rolled Out With This New Safety Feature
  1. Steam Deck Gets a Display-Off Low-Power Mode for Downloads Three Years After Launch
  2. Realme Will Try to Absorb Increased Cost of Components Ahead of Upcoming Product Launches, Executive Says
  3. Motorola Edge 70 Launched With Snapdragon 7 Gen 4 Chipset, Slim 5.99mm Profile: Price, Specifications
  4. Researchers Unveil How Atomic Entanglement Enhances Light Bursts
  5. Lava Agni 4 Confirmed to Launch in Two Colourways; Tipster Leaks Price Range, Key Features
  6. Google Proposes Play Store Reforms in Settlement With Fortnite Maker Epic Games
  7. Scientists Recreate Cosmic ‘Fireballs’ in Lab to Solve Mystery of Missing Gamma Rays
  8. Realme UI 7.0 Launched With Light Glass Design, AI Notify Brief and AI Gaming Coach: See Eligible Phones, Beta Release Schedule
  9. iOS 26.2 Beta 1 Rolled Out to Developers With Enhanced Safety Alerts, Reminder Alarms
  10. Samsung Galaxy S26 Ultra Spotted in Leaked Design Renders That Hint at Rounder Corners
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.