Connect with us

Facebook

Update your WhatsApp, seriously, do it right now

There’s a critical security vulnerability that was patched.

whatsapp
Image: BGR India

Just a heads up, if you buy something through our links, we may get a small share of the sale. It’s one of the ways we keep the lights on here. Click here for more.

Editor’s Note: Listen, before you read any further – if you have WhatsApp installed on your phone, go check for updates. We’ll wait.

Okay, now that you’ve done that – here’s the “why.” A serious vulnerability in the WhatsApp code was enabling attackers to infect phones with spyware, by calling phone numbers over an in-app audio call – even if the person being called didn’t pick up.

That’s pretty serious, although you probably don’t need to worry if your phone was infected. The Facebook-owned company said that the vulnerability was only used on a “select number” of users, who were targeted by “an advanced cyber actor.” According to the Financial Times, the vulnerability was discovered early this month, and the exploit has been patched by WhatsApp on the server side.

The bug let callers inject spyware onto the target phone, even if the call wasn’t answered

Then, the spyware erases the incoming call information, covering its tracks. Among the targets was a prominent London-based human rights lawyer, according to CNN. Thankfully, their phone was attacked after WhatsApp had already fixed the exploitable code.

With WhatsApp’s selling point being end-to-end encryption, the ability to exploit the app is worrisome. WhatsApp has 1.5 billion users worldwide, so the pool of potential targets is huge. Only a few dozen phones were actually hijacked in this attack, which appears to have been carried out by an Israeli company, which is known for working with governments to install spyware.

WhatsApp and Ireland’s Data Protection Commission are both urging users to update their apps, out of an abundance of caution.

Here’s how to update:

On iPhone:
  1. Open the App Store and select updates
  2. Select WhatsApp and Update
On Android devices:
  1. Open the Play Store and tap on the 3 lines in the upper left corner
  2. Select My apps & games from the menu
  3. Select WhatsApp and select Update

What do you think? Do attacks like this make you worried about your security and privacy? Let us know down below in the comments or carry the discussion over to our Twitter or Facebook.

Editors’ Recommendations:

Follow us on Flipboard, Google News, or Apple News

Maker, meme-r, and unabashed geek with nearly half a decade of blogging experience at KnowTechie, SlashGear and XDA Developers. If it runs on electricity (or even if it doesn't), Joe probably has one around his office somewhere, with particular focus in gadgetry and handheld gaming. Shoot him an email at joe@knowtechie.com.

Click to comment

Leave a Reply

Your email address will not be published. Required fields are marked *

More in Facebook