时间:2025-12-27 16:57:03 来源:网络整理编辑:熱點
The past few months have not been good to WhatsApp users. Unfortunately, that doesn't look like it's
The past few months have not been good to WhatsApp users. Unfortunately, that doesn't look like it's about to change any time soon.
The Facebook-owned messaging app acknowledged and patched a major vulnerability that gave hackers the ability to access files on a victim's computer. All you had to do to fall prey to this attack was click a disguised link preview sent via the messaging app. In other words, it would have been an easy mistake for users to make.
Importantly, this did not affect every single WhatsApp user. Rather, a WhatsApp user had to have the iOS version of the messaging app paired to either a PC or MacOS WhatsApp desktop app.
"A vulnerability in WhatsApp Desktop when paired with WhatsApp for iPhone allows cross-site scripting and local file reading," reads the Facebook bug report. "Exploiting the vulnerability requires the victim to click a link preview from a specially crafted text message."

In a Feb. 4 blog post, the security researcher who discovered and disclosed the vulnerability detailed his process and noted that WhatsApp should really get its shit together.
"It is 2020," wrote Gal Weizman, "no product should be allowing a full read from the file system and potentially a [remote code execution] from a single message."
Patrick Wardle, a security researcher at Jamf and founder of Objective-See, told Mashable over Twitter direct message that "often desktop versions of apps aren't as well audited or well written ...and thus often open to attacks."
He added that this specific specific bug "was likely rather trivial to exploit," but cautioned against people freaking out.
"[Still]," wrote Wardle, "a super neat bug, and had the potential to impact lots of users (I use WhatsApp desktop), so definitely happy a security researcher uncovered it and that FB patched it quickly."
We reached out to Facebook in an effort to determine how many people were vulnerable to this exploit and how many, if any, were actually affectedby it. We've received no response as of press time.
Notably, WhatsApp vulnerabilities can have serious consequences. Just this past month, a security firm hired by Amazon CEO Jeff Bezos claimed in a report that the CEO's phone may have been hacked following the receipt of a malicious WhatsApp message. And while Bezos will be fine, people with less power and resources who fall victim to similar attacks may not fare as well.
Facebook is aware of this, but suggests at least some of the blame should lie elsewhere. Following the news of Bezos' hacked phone, the company's vice president of Europe, the Middle East and Africa, Nicola Mendelsohn, suggested to Bloombergthat Apple is the real problem here.
"One of the things that it highlights is actually some of the potential underlying vulnerabilities that exist on the actual operating systems on phones," Mendelsohn told the publication. "From a WhatsApp perspective, from a Facebook perspective, the thing that we care about the most, the thing that we invest in is making sure that the information that people have with us is safe and secure."
SEE ALSO: Mic on Bezos' hacked phone possibly compromised for months
Which, yeah, great. Making sure WhatsApp information is "safe and secure" sounds great, but perhaps that should include not allowing malicious texts that let hackers access victims' computers? Sounds like a good place to start.
Or, if that's too much, maybe Facebook should start recommending Signal.
UPDATE: Feb. 5, 2020, 2:02 p.m. PST:This story has been updated with comment from Patrick Wardle.
TopicsCybersecurityFacebookWhatsApp
Cat gets stuck in the most awkward position ever2025-12-27 16:02
【波盈世界杯】 【深度】瓊阿梅尼揭開利物浦與皇馬的“討論” ( 利物浦,中場 )2025-12-27 15:54
【波盈世界杯】 隨隊晉級8強,曼城官方為福登等5名隊內英格蘭球員送上祝賀 ( 英格蘭,曼城 )2025-12-27 15:48
【波盈世界杯】 ESPN:本2025-12-27 15:46
Here's George Takei chilling in zero gravity for the 'Star Trek' anniversary2025-12-27 15:33
【波盈世界杯】 電訊報 :切爾西專注於中場與後防,沒有簽C羅的計劃 ( 切爾西,赫爾 )2025-12-27 15:29
【波盈世界杯】 熱刺前鋒:哪怕你周薪1000萬 隻要狀態不好 穆裏尼奧都會讓你坐板凳 ( 穆裏尼奧,盧卡斯 )2025-12-27 14:56
【波盈世界杯】 切爾西鼓勵庫利巴利和門迪:很棒的世界杯之旅 ( 世界杯,塞內加爾 )2025-12-27 14:33
There's a big piece of fake chicken stuck to this phone case2025-12-27 14:29
足壇重磅 !曼聯官方:C羅即刻離隊 雙方達成一致 ( 曼聯,他在 )2025-12-27 14:24
Here's George Takei chilling in zero gravity for the 'Star Trek' anniversary2025-12-27 16:35
格雷澤宣布考慮出售球隊後,曼聯股價暴漲17%+市值大增4萬億美元 ( 曼聯,俱樂部 )2025-12-27 16:34
官宣!曼聯開除C羅,世界杯後尋找下家,切爾西拜仁皇馬在列 ( 曼聯,世界杯 )2025-12-27 16:03
【波盈世界杯】 在熱刺、西漢姆 、那不勒斯的關注下 ,23歲的中場球員偏愛加盟羅馬 ( 球員,弗拉 )2025-12-27 15:56
17 questions you can answer if you're a good communicator2025-12-27 15:41
【波盈世界杯】 每體:瓜迪奧拉接近與曼城完成續約 ,他和俱樂部已開始談判 ( 迪奧,曼城 )2025-12-27 15:02
【波盈足球】 曼聯官方 :將評估戰略選擇,考慮包括出售等可能性 ( 曼聯,俱樂部 )2025-12-27 14:59
【波盈世界杯】 ESPN:本2025-12-27 14:47
Man stumbles upon his phone background in real life2025-12-27 14:39
【波盈世界杯】 拉拉納:英格蘭中場三人組很出色,有點像克洛普初期的利物浦 ( 世界杯,中場 )2025-12-27 14:24