Data: CASIE
Negative Trigger
that
the
flaw
was reported
Vulnerability-related.DiscoverVulnerability
to
WhatsApp
in
August
,
and
has been patched
Vulnerability-related.PatchVulnerability
in
the
latest
version
–
so
you
’
ll
want
to
check
for
an
update
.
Google
Project
Zero
whizkid
and
Tamagotchi
whisperer
Natalie
Silvanovich
discovered and reported
Vulnerability-related.DiscoverVulnerability
the
flaw
,
a
memory
heap
overflow
issue
,
directly
to
WhatsApp
in
August
.
Now
that
a
fix
is out
Vulnerability-related.PatchVulnerability
,
Silvanovich
can
go public
Vulnerability-related.DiscoverVulnerability
with
details
on
the
potentially
serious
flaw
.
According
to
Silvanovich’s report
Vulnerability-related.DiscoverVulnerability
,
the
bug
is
triggered
when
a
user
receives
a
malformed
RTP
packet
,
triggering
the
corruption
error
and
crashing
the
application
.
In
practice
,
the
malformed
packet
that
triggers
the
crash
could
be
sent
via
a
simple
call
request
.
“
This
issue
can
occur
when
a
WhatsApp
user
accepts
a
call
from
a
malicious
peer
,
”
Silvanovich
explained
.
It
’
s
not
clear
whether
the
WhatsApp
security
flaw
could
be exploited
Vulnerability-related.DiscoverVulnerability
for
remote
code
execution
,
but
this
is
a
possibility
,
and
a
sufficient
risk
for
a
fellow
Google
researcher
to
describe
Vulnerability-related.DiscoverVulnerability
it
as
‘
a
big
deal.
’
“
This
is
a
big
deal
,
”
tweeted
Travis
Ormandy
.
“
Just
answering
a
call
from
an
attacker
could
completely
compromise
WhatsApp.
”
The
same
vulnerability
was present in
Vulnerability-related.DiscoverVulnerability
the
Android
app
,
which
has also been patched
Vulnerability-related.PatchVulnerability
.
The
Register
says
it
is
still
waiting
to
hear
from
Google
on
more
details
,
for
example
whether
the
desktop
app
is similarly affected
Vulnerability-related.DiscoverVulnerability
.
It
’
s
not
the
first
time
of
late
that
a
WhatsApp
security
issue
has been identified
Vulnerability-related.DiscoverVulnerability
.
Back
in
August
,
it
was discovered
Vulnerability-related.DiscoverVulnerability
that
it
was
possible
for
an
attacker
to
change
both
the
content
and
the
sender
of
a
WhatsApp
message
after
you
’
ve
received
it
.