27 C
Jaipur
Saturday, October 24, 2020

WhatsApp Discloses 6 Bugs That Allows Attackers to Execute Code

Must read

Maharashtra Government invites Tesla to set up a local plant | TechRadar

Elon Musk recently talked about how Tesla would come to India in 2021. While that could have many meanings, local governments are now taking...

VPN’s coming-of-age: A discussion with the ExpressVPN co-founders

It feels like VPNs are suddenly everywhere. What was once a technology used only by IT professionals and large businesses has now become a...

World Series live stream 2020: how to watch Dodgers vs Rays game 3 anywhere now

In a matter of days, the year's shortened MLB season will crown a new champion, but who will it be? The 2020 World Series...

Skype is back, and wants to take on Zoom

The pandemic has seen demand for video conferencing software skyrocket as businesses use the technology to work from home and students use it for...

WhatsApp disclosed 6 security bugs through their dedicated security advisory site that allows attackers to execute remote code.

WhatsApp is a messaging app used by more than two billion users around the world. All the vulnerabilities are disclosed in dedicated security advisory site aimed to provide more transparent details about vulnerabilities for users and security professionals.

“We take the security of our users very seriously and we provide industry-leading protection for our users around the world. Our security team at WhatsApp works with experts around the world to stay ahead of potential threats,” reads the blog post.

6 Security Bugs

CVE-2020-1894

A stack write overflow which allows attackers to execute arbitrary code when playing a specially crafted push to talk message.

It affects WhatsApp for Android before v2.20.35, WhatsApp Business for Android before v2.20.20, WhatsApp for iPhone before v2.20.30, and WhatsApp Business for iPhone before v2.20.30.

CVE-2020-1891

A user-controlled parameter used in a video call in WhatsApp allowed an out-of-bounds write on 32-bit devices.

The bug affects WhatsApp for Android before v2.20.17, WhatsApp Business for Android before v2.20.7, WhatsApp for iPhone before v2.20.20, and WhatsApp Business for iPhone before v2.20.20.

CVE-2020-1890

A URL validation issue in WhatsApp for Android before v2.20.11 and WhatsApp Business for Android before v2.20.2 would allow the execution of malformed data in a sticker message that loads images from URL controlled by the sender.

CVE-2020-1889

A security feature bypass issue in WhatsApp Desktop versions before v0.3.4932 could have allowed for sandbox escape in Electron and escalation of privilege if combined with a remote code execution vulnerability inside the sandboxed renderer process.

CVE-2020-1886

A buffer overflow in WhatsApp for Android before v2.20.11 and WhatsApp Business for Android before v2.20.2 could have allowed an out-of-bounds write via a specially crafted video stream after receiving and answering a malicious video call.

CVE-2019-11928

An input validation issue in WhatsApp Desktop versions before v0.3.4932 could have allowed cross-site scripting upon clicking on a link from a specially crafted live location message.

You can follow us on LinkedinTwitterFacebook for daily Cybersecurity updates

Also Read:

WhatsApp Bug Leaked Personal Phone Numbers in Google Search Results

Critical WhatsApp Vulnerability Let Hackers to Access the Local System Files on Mac & Windows

Source link

- Advertisement -

More articles

LEAVE A REPLY

Please enter your comment!
Please enter your name here

Latest article

Maharashtra Government invites Tesla to set up a local plant | TechRadar

Elon Musk recently talked about how Tesla would come to India in 2021. While that could have many meanings, local governments are now taking...

VPN’s coming-of-age: A discussion with the ExpressVPN co-founders

It feels like VPNs are suddenly everywhere. What was once a technology used only by IT professionals and large businesses has now become a...

World Series live stream 2020: how to watch Dodgers vs Rays game 3 anywhere now

In a matter of days, the year's shortened MLB season will crown a new champion, but who will it be? The 2020 World Series...

Skype is back, and wants to take on Zoom

The pandemic has seen demand for video conferencing software skyrocket as businesses use the technology to work from home and students use it for...

Illinois vs Wisconsin live stream: how to watch Big Ten college football anywhere

While NCAA college football has been in action for a few weeks, the 2020/21 season only feels truly underway now the Big Ten are...