WhatsApp vulnerability exploited to infect phones with Israeli spyware [telecom]

May 15, 2019 0 Replies
WhatsApp vulnerability exploited to infect phones with Israeli spyware [telecom] open original image

WhatsApp vulnerability exploited to infect phones with Israeli spyware



Attacks used app's call function. Targets didn't have to answer to be infected.



By Dan Goodin



Attackers have been exploiting a vulnerability in WhatsApp that allowed them to infect phones with advanced spyware made by Israeli developer NSO Group, the Financial Times reported on Monday, citing the company and a spyware technology dealer.



A representative of WhatsApp, which is used by 1.5 billion people, told Ars that company researchers discovered the vulnerability earlier this month while they were making security improvements. CVE-2019-3568, as the vulnerability has been indexed, is a buffer overflow vulner- ability in the WhatsApp VOIP stack that allows remote code execution when specially crafted series of SRTCP packets are sent to a target phone number, according to this advisory.



formatting link


Join the Discussion

Have something to add? Share your thoughts — no account required.

Didn't find your answer?

Ask the community — no account required