News

WhatsApp patches vulnerability in image filter function that could have led to data exposure

Ireland fines WhatsApp 225m euros for breaching EU privacy laws

September 3, 2021 10:06 AM


Twitter Share Facebook Share WhatsApp Share

WhatsApp has patched a vulnerability that could allow an attacker to read sensitive information from the app's memory, including private messages using a specially crafted image.

The vulnerability was reported to WhatsApp by cybersecurity firm Check Point Research, and it existed within the image filter function of WhatsApp for Android and WhatsApp Business for Android that allows users to add filters to their images.

The Facebook-owned company fixed the security issue after it was reported by Check Point researchers and claimed that there was no evidence that the vulnerability was ever abused.

Called “Out-Of-Bounds read-write vulnerability”, the issue was disclosed to WhatsApp by Check Point Research on November 10, 2020. WhatsApp took some time in fixing the bug and issued a patch in February. It was provided to end-users through version 2.21.1.13 of both WhatsApp for Android and WhatsApp Business for Android apps.

Researchers at Check Point Research were able to discover the vulnerability that is technically a memory corruption issue while looking at the way WhatsApp processes and sends images on its platform. During the research, it was found that the image filter function of the messaging app crashes when it was used with some specially-designed GIF files. That brought the researchers to the point from where they were able to spot the loophole.

According to Check Point Research, the vulnerability could be triggered after a user opens an attachment containing a maliciously crafted image file, tries to apply a filter, and then sends the image with the filter applied back to the attacker. The researchers, thus, noted that hackers would have required “complex steps and extensive user interaction” to exploit the issue.

However, if it could be successfully exploited, the vulnerability is claimed to allow hackers to read sensitive information from WhatsApp memory that include private messages and previously shared images and videos.

“Once we discovered the security vulnerability, we quickly reported our findings to WhatsApp, who was cooperative and collaborative in issuing a fix. The result of our collective efforts is a safer WhatsApp for users worldwide,” said Oded Vanunu, Head of Products Vulnerabilities Research at Check Point, in a prepared statement.

WhatsApp has listed the details of the vulnerability on its security advisories site as CVE-2020-1910. The platform added two new checks on source and filter images to restrict memory access.

“People should have no doubt that end-to-end encryption continues to work as intended and people's messages remain safe and secure,” WhatsApp said in its statement given to Check Point Research. “This report involves multiple steps a user would have needed to take and we have no reason to believe users would have been impacted by this bug. That said, even the most complex scenarios researchers identify can help increase security for users.”

 
Ireland fines WhatsApp
Ireland on Thursday slapped Facebook's WhatsApp messaging service with a record fine for breaching EU data privacy laws after European regulators demanded the penalty be increased.

Ireland's Data Protection Commission was entrusted with the case because Facebook's European headquarters are situated in the country.

"And following this reassessment the DPC has imposed a fine of 225 million euros ($267 million) on WhatsApp," the commission said, by far the largest penalty it has ever issued to a company, dwarfing the 450,000-euro fine imposed on Twitter last year. 

As Ireland hosts the regional headquarters of a number of major tech players such as Apple, Google and Twitter, the DPC has been largely responsible for policing adherence to the EU's landmark General Data Protection Regulation (GDPR) charter.

But Ireland has come under pressure for not taking a firm enough line against tech giants, who are generally understood to be drawn to the country by its low corporate tax rate of 12.5 percent.

WhatsApp said it would appeal the decision.

"We disagree with the decision today" it said in a statement, calling the penalties "entirely disproportionate."

- 'Dissuasive fine' -
The DPC launched the WhatsApp probe in December 2018 to examine whether the messaging app "discharged its GDPR transparency obligations" with regard to telling users how their data would be processed between WhatsApp and other Facebook companies.

In an initial finding submitted to other European regulators for approval last December, the DPC proposed imposing a fine of between 30 and 50 million euros, but a number of national regulators rejected the figure, triggering the launch of a dispute resolution process in June.

Last month, the European Data Protection Board (EDPB) instructed the DPC to increase the fine, with Germany's regulator leading the calls for the penalty to be higher. 

The EDPB said that the fine had to "reflect a significant level of non-compliance which impact on all of the processing carried out by WhatsApp" in Ireland.

The fine had to be "effective, dissuasive and proportionate," it said. 

Hailed as a potent weapon to bring tech titans to heel, the GDPR endowed national watchdogs with cross-border powers and the possibility to impose sizeable fines for data misuse.

But Germany's data protection commissioner, Ulrich Kelber, in March wrote an open letter criticising the DPC for the "extremely slow" way it handled GDPR complaints.



Most Read

  1. New Iceland plant scales up CO2 removal from air New Iceland plant scales up CO2 removal from air
  2. Aamir Liaquat video leak: YouTuber Yasir Shami gets bail Aamir Liaquat video leak: YouTuber Yasir Shami gets bail
  3. Alia Bhatt's deepfake video creates a stir on social media Alia Bhatt's deepfake video creates a stir on social media
  4. Application seeking setting up of Lorenzo Gay Club in Abbottabad rejected Application seeking setting up of Lorenzo Gay Club in Abbottabad rejected
  5. Hollywood biggies recreate Urfi’s iconic OOTDs at Met Gala 2024 Hollywood biggies recreate Urfi’s iconic OOTDs at Met Gala 2024
  6. Ranveer Singh clears Instagram feed of wedding photos with Deepika Ranveer Singh clears Instagram feed of wedding photos with Deepika

Opinion

  1. Military Establishment rules out any deal with what it terms a ‘bunch of anarchists’
    Military Establishment rules out any deal with what it terms a ‘bunch of anarchists’

    By Salim Bokhari

  2. 9th May - A year later
    9th May - A year later

    By Mutaza Solangi

  3. Everything but the truth in Telegraph
    Everything but the truth in Telegraph

    By Mutaza Solangi

  4. PM Shehbaz Sharif, WEF and Pakistan
    PM Shehbaz Sharif, WEF and Pakistan

    By Naveed Aman Khan

  5. Employing global best practices in Pakistan-Saudi ties
    Employing global best practices in Pakistan-Saudi ties

    By Nasim Zehra

  6. PML-N smashed PTI in by-polls
    PML-N smashed PTI in by-polls

    By News Desk