Sources from San Francisco stated that a security bug has been found in Facebook owned instant messenger WhatsApp that could let attackers to obtain access to a device and steal data by sending a malicious GIF file. Meanwhile the danger stems from a double-free bug in WhatsApp, according to a researcher going by the nickname Awakened.

Related image

Reportedly a double-free vulnerability is a memory corruption anomaly that could crash an application or open up an exploit vector that attackers can abuse to gain access to users' device. Furthermore according to Awakened's post on GitHub, the flaw resided in WhatsApp's Gallery view implementation that is used to generate previews for photographs, videos and GIFs. Hence all it takes to perform the attack is to craft a malicious GIF, and wait for the user to open the WhatsApp gallery.



According to a report in Gizmodo "The exploit works well until WhatsApp version 2.19.230. The vulnerability is officially patched in WhatsApp version 2.19.244". Further the bug also works for Android 8.1 and Android 9.0 OS but does not work for Android 8.0 and below. In the older Android versions, double-free could still be triggered. This is because of the malloc calls by the system after the double-free, the app just crashes before reaching to the point that we could control the PC register.


మరింత సమాచారం తెలుసుకోండి: