Patched WhatsApp Vulnerability Could Have Exposed Users Data
Summary
Security researchers with Check Point recently released information on a vulnerability that existed within WhatsApp that could have been exploited to gain illegal access to sensitive user information. The issue has since been patched by WhatsApp and does not affect current versions of the application, but Check Point published their full report on it just now. The issue in question is codified as CVE-2020-1910 and has been assigned a high base score of 7.8. While the steps and circumstances surrounding the exploitable vulnerability are a bit convoluted, they could be reproduced easily in testing. When an app is as popular as WhatsApp, with its billions of users worldwide, the potential for criminals abusing similar issues and zero-day vulnerabilities and harvesting immense amounts of data even from a tiny fraction of the applications user base is considerable.