Security vulnerabilities found in WhatsApp could allow hackers to alter messages and tamper with conversations, security researchers have revealed.
Research conducted by Dikla Barda, Roman Zaikin and Oded Vanunu from cybersecurity firm Check Point showed three particular attack methods that can be used to exploit the vulnerabilities – all of which involve social engineering tactics.
In a blog post, the team explained that the WhatsApp security vulnerabilities could “enable threat actors to intercept and manipulate messages sent in both private and group conversations, giving the attackers the power to create and spread misinformation from what appear to be trusted sources”.
Through the three possible methods, threat actors may use the ‘quote’ feature in a group conversation to change the identity of the sender, even if that person is not a member of the group. Similarly, hackers could alter the text of someone else’s reply, which researchers said essentially puts “words in their mouth”.
Finally, a threat actor could have the ability to send a private message to another group participant that is disguised as a public message for all. Through this method, when the targeted individual responds it would be visible to everyone in the conversation.
Check Point confirmed that the third flaw has since been resolved. However, the researchers noted: “We found that it is still possible to manipulate quoted messages and spread misinformation from what appear to be trusted sources.”
- Twitter may have shared user data with third parties without permission
- Barclays’ second Eagle Lab to open in Aberdeen
- Scots turn to streaming services as traditional TV viewing declines
Given that WhatsApp has recently been found to be a key tool to spread misinformation and fake news – with the Brazilian elections a prime example – the Check Point team emphasised the danger of these particular flaws.
“From Check Point Research’s perspective, we believe these vulnerabilities to be of the utmost importance and require attention,” they said.
WhatsApp, which is owned by Facebook, has more than 1.5 billion users spanning around 180 countries globally. On average, WhatsApp users check the app more than 23 times a day. The popularity and global use of this app, Check Point suggested, means this bug could potentially affect millions of users.
Speaking at the Black Hat conference in Las Vegas, USA, Vanunu demonstrated the team’s research. During the talk, Vanunu explained that the vulnerabilities have existed for about a year – despite the fact that Check Point notified the company toward the end of 2018.
Responding to Check Point’s research, Facebook told the Financial Times that the bugs were due to “limitations that can’t be solved due to their structure and architecture”.






