WhatsApp Account is being hacked by using WhatsApp call
Google Project Zero security researcher Natalie Silvanovich which is a researcher , who is involved in researching vulnerabilities and flaws in different apps from decades as they recently found critical vulnerability in WhatsApp messenger.
These vulnerability can hack mobile phone as the control will gone fully controlled by hacker and your WhatsApp will crashed instantly.
It is caused be heaping overflow of malicious memory that is inserted by the hacker during calling , this malicious data is packed into a malformed RTP packet.
After calling bu hacker , its start processing and when user received it it gone initiate and starting attacking user WhatsApp messenger . Most of the RTP (Real-time Transport Protocol) is effected by these vulnerabilities if these are found in Android and iOS apps but WhatsApp Web that relies on WebRTC for video calls is not going to effecting by these vulnerabilities.
Memory corruption bug in WhatsApp's non-WebRTC video conferencing implementation https://t.co/5sCmNznh4P— Natalie Silvanovich (@natashenka) October 9, 2018
You can found proof-of-concept which is published by Silvanovich which is the sample instructions for reproducing the WhatsApp attack. Silvanovich explained as this type of attack is only worked with memory corruption.
Google Project Zero researcher, Tavis Ormandy, claims that
This is a big deal. Just answering a call from an attacker could completely compromise WhatsApp.

No comments: