Skip to content
General

WhatsApp vulnerability allowed government-grade spyware to be installed

By Minjun Park
1 min read
us it internet technology telecommunication facebo 46010783
us it internet technology telecommunication facebo 46010783
In this article (5)

WhatsApp, one of the most popular messaging apps out there, has once again been the subject of hacking, but this time the method used involves government-grade spyware. Although we have no information that would confirm who’s behind the attack, the spyware used is usually sold to governments.

The vulnerability discovered by WhatsApp just a few weeks ago would allow a caller to install spyware on the device being called, regardless of whether or not the could be answered.

The spyware installed was made by Israel-based NSO Group Pegasus, and is usually licensed to governments that want to hack targets of investigations and gain access to multiple aspects of their devices.

It’s unclear how many Android and iOS devices were affected by the vulnerability, but as you can imagine, anyone with access to the spyware could hack any WhatsApp user. On the bright side, WhatsApp said that it took less than 10 days after it discovered the security issue to patch it. The company also believes that only a relatively small number of users were targeted by the attack.

This attack has all the hallmarks of a private company known to work with governments to deliver spyware that reportedly takes over the functions of mobile phone operating systems. We have briefed a number of human rights organizations to share the information we can, and to work with them to notify civil society.

If you have WhatsApp installed on your phone, installing the latest version of the app will render the attack inoperable, even if it was infected with the government-grade spyware.

Questions & Answers

Q.

How did the attackers manage to install the spyware on devices?

A.

The vulnerability allowed spyware to be installed simply by placing a call to the target device. This occurred regardless of whether the call was answered by the user, making the attack highly effective.

Q.

Which company developed the spyware used in this attack?

A.

The spyware installed was developed by NSO Group Pegasus, an Israel-based company. Their software is typically licensed to governments for use in investigations against specific targets.

Q.

How quickly did WhatsApp address this security vulnerability?

A.

WhatsApp managed to patch the security issue very quickly after its discovery. The company reported that it took less than 10 days to resolve the problem.

Q.

What should users do if they are concerned their device might have been affected?

A.

Users concerned about the vulnerability should update their WhatsApp application to the latest version. Installing the update will make the attack inoperable, even if the device was previously infected.

Reader pulse

Does this vulnerability change your trust in messaging apps for business?

20,295 votes so far

Weekly Briefing

Asia's retail intelligence, in your inbox

Monday, Wednesday and a Friday Weekly Wrap: the retail stories, numbers and moves that mattered across Asia. Nothing else, and you can unsubscribe in one click.

  • Top industry moves and market shifts
  • Weekly data-driven analysis from across Asia
  • Monday, Wednesday and the Friday Weekly Wrap

Read by retail operators, investors and brand teams across Asia.

Protected by a quick human check. No spam, ever. Unsubscribe in one click.

SecureGDPR ready