Now on Demand: Zero Trust Strategies Summit - Access All Sessions
Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Vulnerabilities

vCard Vulnerability Exposes WhatsApp Users

A vulnerability discovered in WhatsApp Web, the web-based extension of the WhatsApp mobile application, can be exploited by attackers to trick users into executing arbitrary code on their machines.

A vulnerability discovered in WhatsApp Web, the web-based extension of the WhatsApp mobile application, can be exploited by attackers to trick users into executing arbitrary code on their machines.

Discovered by Check Point security researcher Kasif Dekel, the vulnerability can be exploited by simply sending a vCard contact card containing malicious code to a WhatsApp user. As soon as the seemingly innocent vCard is opened in WhatsApp Web, the malicious code in it can run on the target machine.

This vulnerability allows cybercriminals to compromise the affected computer by distributing all types of malware, including ransomware, bots, and remote access tools (RATs), Check Point’s researcher explains.

The underlying issue lies in the improper filtering of contact cards that are sent using the popular ‘vCard’ format. “By manually intercepting and crafting XMPP requests to the WhatsApp servers, it was possible to control the file extension of the contact card file,” the Check Point researcher explained in a blog post.

An attacker can inject a command in the name attribute of the vCard file, separated by the ‘&’ character. Windows automatically tries to run all lines in the file, including the injection line, when the vCard is opened.

This attack does not require XMPP interception of crafting, due to the fact that anyone can create such a contact with an injected payload, directly on the phone, Check Point notes. As soon as the contact is ready, the attacker only needs to share it through the WhatsApp client to unsuspicious users.

Check Point also explains that WhatsApp failed to validate the vCard format or the contents of the file, and that even an exe file could have been sent this way. Even more, malware could have been attached to a displayed icon, opening a vast world of opportunity for cybercriminals and scammers

Over the past several years, WhatsApp has grown to become one of the popular messaging services on mobile phones, with over 900 million users as of this month, and it has extended to the desktop as well, where it has over 200 million users.

Advertisement. Scroll to continue reading.

WhatsApp Web provides users with access to all of the messages that they have sent or received, including includes images, videos, audio files, locations and contact cards, and keeps all content synchronized with the phone, so that users can access it on both desktop and mobile devices.

Additionally, the web-based interface allows users to view all of the sent or received attachments, as long as they are accessible through the mobile application, including images, audio and video files, location info, and contact cards.

To connect with other people on WhatsApp, users need to know the phone number associated with their accounts, and cybercriminals can take advantage of this to target individuals when exploiting the newly discovered vulnerability.

According to the security firm, WhatsApp has acknowledged the security issue and released a fix for it on Aug. 27. Users of WhatsApp Web should update their software as soon as possible to ensure that their computers are protected. WhatsApp Web v0.1.4481 and later include the fix for this vulnerability.

Written By

Click to comment

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join SecurityWeek and Hitachi Vantara for this this webinar to gain valuable insights and actionable steps to enhance your organization's data security and resilience.

Register

Event: ICS Cybersecurity Conference

The leading industrial cybersecurity conference for Operations, Control Systems and IT/OT Security professionals to connect on SCADA, DCS PLC and field controller cybersecurity.

Register

People on the Move

Former Darktrace CEO Poppy Gustafsson has joined the UK government as Minister for Investment.

Nupur Goyal has joined cloud identity security and management solutions provider Saviynt as VP of Product Marketing.

Threat intelligence firm Intel 471 has appointed Mark Huebeler as its COO and CFO.

More People On The Move

Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.