WhatsApp Web Security Flaw Can Affect Up to 200 Million Users: Report

Advertisement
By Manish Singh | Updated: 9 September 2015 12:25 IST

A newly found vulnerability in WhatsApp Web, the Web-based interface of the popular instant messaging client, allows attackers to trick users into executing arbitrary code on their computers, a security firm reports. The vulnerability affects more than 200 million people who use WhatsApp Web. WhatsApp has since updated its Web client to patch the bug in the latest version.

The 'MaliciousCard' vulnerability can be exploited by simply sending a vCard contact card containing malicious code to a victim's account, reports security firm Check Point. Once the victim opens the alleged contact, it starts to distribute bots, ransomware, and other malware files.

Since the business contact card looks perfectly legitimate, it is impossible for a user to know if the contact is riddled with malicious code.

Advertisement

The security firm noted that it informed WhatsApp about the vulnerability, and the messaging service issued an update on August 21 that fixes the bug. WhatsApp Web v0.1.4481 or later are not affected with the vulnerability.

Advertisement

The vulnerability lies in the improper filtering of contact cards sent in the vCard format in older versions of WhatsApp. The attacker can inject a command in the name attribute of the vCard file, separated by the ampersand character. Windows would automatically try to run all lines in the code. It is not known whether Mac users are affected by the vulnerability.

WhatsApp fails to validate the vCard format and the contents of the file, the firm further noted. One could send an executable file and WhatsApp wouldn't be able to flag or block it.

Advertisement

WhatsApp, which is available across multiple platforms, recently announced that it reached 900 million monthly active users. WhatsApp Web, which offers several of the mobile app's functionalities including the ability to send and receive text and audio notes, is used by more than 200 million users.

 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Advertisement

Related Stories

Popular Mobile Brands
  1. Starlink Will Offer Unlimited Satellite Internet in India at This Price
  2. OnePlus 15R Roundup: Price in India, Specs and Everything We Know So Far
  3. Jolla Phone Launched With 5,500mAh Replaceable Battery, Sailfish OS 5
  4. iPhone 16 Deal Alert: Get It for Just Rs 65,900 Effective Price
  5. Airtel Partners With Google to Launch RCS Messaging in India
  6. Realme Narzo 90 Series 5G India Launch Announced
  7. Samsung's One UI 8.5 Beta Released: See Eligible Phones, Regions
  8. OnePlus Pad Go 2 Key Features Revealed: Here's When It Goes on Sale in India
  9. OnePlus Pad Go 2 First Impressions
  10. Infinix Note 60, Note 60 Edge, Note 60 Pro Reportedly Spotted on SDPPI Website
  1. OnePlus Pad Go 2 Key Specifications and Sale Date Revealed; Will Feature Dimensity 7300-Ultra SoC
  2. OpenAI Claims Increased Enterprise Usage Amid CEO’s Code Red Declaration
  3. Samsung's One UI 8.5 Beta Update Rolls Out to Galaxy S25 Series in Multiple Regions
  4. Elon Musk Says Grok 4.20 AI Model Could Be Released in a Month
  5. Xiaomi 17 Global Variant Listed on Geekbench, Tipped to Launch in India by February 2026
  6. James Gunn's Superman to Release on JioHotstar on December 11: What You Need to Know
  7. The Boys Season 5 OTT Release Date: When and Where to Watch the Final Season Online?
  8. The Strangers Chapter 2 Now Available on Rent on Amazon Prime Video, Apple TV, and More
  9. Meta Acquires AI Wearables Startup Limitless, Could Expand Its Hardware Offerings
  10. Airtel Reportedly Partners With Google to Launch RCS Messaging for Users in India
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.