HT TECH wants to start sending you push notifications. Click allow to subscribe

WhatsApp’s MP4 security vulnerability: What it is and should you be worried?

WhatsApp last week reported MP4 video file-related vulnerability for Android and iPhone users. Here’s everything you need to know about the new bug.

By: HT CORRESPONDENT
Updated on: Aug 20 2022, 18:00 IST
Should you be worried? (REUTERS)
Should you be worried? (REUTERS)

WhatsApp last week fixed a new security vulnerability that could have allowed hackers to gain access to users' sensitive data using common MP4 video files. The new vulnerability comes days after WhatsApp reported spyware attack which led to snooping on 1,400 individuals around the world. Here's everything you need to know about the latest WhatsApp bug.

What it is

You may be interested in

Mobiles Tablets Laptops
Apple iPhone 15 Pro Max
  • Black Titanium
  • 8 GB RAM
  • 256 GB Storage
₹156,900
Check details
28% OFF
Samsung Galaxy S23 Ultra 5G
  • Green
  • 12 GB RAM
  • 256 GB Storage
₹107,999₹149,999
Buy now
Google Pixel 8 Pro
  • Obsidian
  • 12 GB RAM
  • 128 GB Storage
₹106,998
Check details
Apple iPhone 15 Plus
  • Black
  • 6 GB RAM
  • 128 GB Storage
₹87,900
Check details
21% OFF
Acer Swift Go SFG14 41 NX KG3SI 002 Laptop
  • Pure Silver
  • 8 GB RAM
  • 512 GB SSD
₹58,990₹74,999
Buy now
41% OFF
Acer Aspire 5 A515 57G Laptop
  • Gray
  • 16 GB RAM
  • 512 GB SSD
₹52,990₹89,999
Buy now
41% OFF
Acer Aspire 3 A315 24 NX KDESI 004 Laptop
  • Silver
  • 8 GB RAM
  • 512 GB SSD
₹34,490₹57,999
Buy now
40% OFF
Asus VivoBook 15 X515JA BQ322WS Laptop
  • Transparent Silver
  • 8 GB RAM
  • 512 GB SSD
₹31,350₹51,990
Buy now
35% OFF
Xiaomi Pad 6
  • Mist Blue
  • 6 GB RAM
  • 128 GB Storage
₹25,999₹39,999
Buy now
55% OFF
Lenovo Tab M10 5G
  • Abyss Blue
  • 6 GB RAM
  • 128 GB Storage
₹20,999₹47,000
Buy now
32% OFF
Realme Pad 2
  • Imagination Grey
  • 6 GB RAM
  • 128 GB Storage
₹19,668₹28,999
Buy now
Honor Pad X9
  • Gray
  • 4 GB RAM
  • 128 GB Storage
₹16,998
Check details

Facebook revealed that hackers used 'specially crafted MP4 file' to trigger the remote code execution (RCE) and denial of service (DoS) cyber attack. The new bug exploited a familiar "stack-based buffer overflow" which was used by the Pegasus spyware earlier this year.

Also read: Looking for a smartphone? To check mobile finder click here.

Here's what Facebook described the vulnerability as: "A stack-based buffer overflow could be triggered in WhatsApp by sending a specially crafted MP4 file to a WhatsApp user. The issue was present in parsing the elementary stream metadata of an MP4 file and could result in a DoS or RCE."

CERT-In, India's nodal agency for handling cyber-security related threats, also had similar findings about the vulnerability.

"A stack-based buffer overflow vulnerability exists in WhatsApp due to improper parsing of elementary metadata of an MP4 file. A remote attacker could exploit this vulnerability by sending a special crafted MP4 file to the target system. This could trigger a buffer overflow condition leading to execution of arbitrary code by the attacker. The exploitation doesn't require any form of authentication from the victim and executes on downloading of malicious crafted MP4 file on the vicitims system," said the agency.

ALSO READ: WhatsApp vulnerabilities that put users' data at risk

Who was affected? Should you be worried?

According to Facebook, the security vulnerability was found on Android versions older than 2.19.274. It was also discovered on iOS version older than 2.19.100. Business for Android versions prior to 2.19.104; Business for iOS versions prior to 2.19.100; and Windows Phone versions before and including 2.18.368 were also impacted.

While CERT-In asked users to update their WhatsApp app, the instant messaging company said no users were affected by the latest vulnerability.

"WhatsApp is constantly working to improve the security of our service. We make public, reports on potential issues we have fixed consistent with industry best practices. In this instance, there is no reason to believe users were impacted," said WhatsApp spokesperson in a statement.

Catch all the Latest Tech News, Mobile News, Laptop News, Gaming news, Wearables News , How To News, also keep up with us on ,Twitter, Facebook, , and Instagram. For our latest videos, subscribe to our YouTube channel.

First Published Date: 19 Nov, 11:42 IST

Sale

Mobiles Tablets Laptops
4% OFF
Samsung Galaxy S24 Ultra
  • Titanium Black
  • 12 GB RAM
  • 256 GB Storage
₹129,999₹134,999
Buy now
7% OFF
Apple iPhone 15 Pro Max
  • Black Titanium
  • 8 GB RAM
  • 256 GB Storage
₹148,900₹159,900
Buy now
13% OFF
Xiaomi 14
  • Matte Black
  • 12 GB RAM
  • 512 GB Storage
₹69,999₹79,999
Buy now
10% OFF
Apple iPhone 15 Plus
  • Black
  • 6 GB RAM
  • 128 GB Storage
₹80,990₹89,900
Buy now
33% OFF
Xiaomi Pad 6
  • Mist Blue
  • 6 GB RAM
  • 128 GB Storage
₹26,999₹39,999
Buy now
28% OFF
Realme Pad 2
  • Imagination Grey
  • 6 GB RAM
  • 128 GB Storage
₹17,999₹24,999
Buy now
24% OFF
Samsung Galaxy Tab A7 Lite
  • Silver
  • 3 GB RAM
  • 32 GB Storage
₹9,710₹12,700
Buy now
18% OFF
Samsung Galaxy Tab S9 5G 256GB
  • Graphite
  • 8 GB RAM
  • 256 GB Storage
₹93,648₹113,798
Buy now
23% OFF
Infinix INBook X1 Neo XL22 Laptop Intel Celeron Quad Core 8 GB 256 GB SSD Windows 11
  • Blue
  • 4 GB RAM
  • 128 GB SSD
₹22,990₹29,990
Buy now
28% OFF
Asus ROG Zephyrus G14 GA402NU N2023WS Laptop
  • Eclipse Gray
  • 16 GB RAM
  • 1 TB SSD
₹144,990₹201,990
Buy now
29% OFF
Asus VivoBook Pro 15 OLED M6500IH L1701WS Laptop
  • Quiet Blue
  • 16 GB RAM
  • 512 GB SSD
₹58,990₹82,990
Buy now
22% OFF
Asus ROG Strix G15 G512LV AZ225T Laptop
  • Glacier Blue
  • 16 GB RAM
  • 1 TB SSD
₹70,990₹90,990
Buy now