WhatsApp vulnerability allowed government-grade spyware to be installed

In this article (5)
WhatsApp, one of the most popular messaging apps out there, has once again been the subject of hacking, but this time the method used involves government-grade spyware. Although we have no information that would confirm who’s behind the attack, the spyware used is usually sold to governments.
The vulnerability discovered by WhatsApp just a few weeks ago would allow a caller to install spyware on the device being called, regardless of whether or not the could be answered.
The spyware installed was made by Israel-based NSO Group Pegasus, and is usually licensed to governments that want to hack targets of investigations and gain access to multiple aspects of their devices.
It’s unclear how many Android and iOS devices were affected by the vulnerability, but as you can imagine, anyone with access to the spyware could hack any WhatsApp user. On the bright side, WhatsApp said that it took less than 10 days after it discovered the security issue to patch it. The company also believes that only a relatively small number of users were targeted by the attack.
This attack has all the hallmarks of a private company known to work with governments to deliver spyware that reportedly takes over the functions of mobile phone operating systems. We have briefed a number of human rights organizations to share the information we can, and to work with them to notify civil society.
If you have WhatsApp installed on your phone, installing the latest version of the app will render the attack inoperable, even if it was infected with the government-grade spyware.
Questions & Answers
Q.How did the attackers manage to install the spyware on devices?
How did the attackers manage to install the spyware on devices?
The vulnerability allowed spyware to be installed simply by placing a call to the target device. This occurred regardless of whether the call was answered by the user, making the attack highly effective.
Q.Which company developed the spyware used in this attack?
Which company developed the spyware used in this attack?
The spyware installed was developed by NSO Group Pegasus, an Israel-based company. Their software is typically licensed to governments for use in investigations against specific targets.
Q.How quickly did WhatsApp address this security vulnerability?
How quickly did WhatsApp address this security vulnerability?
WhatsApp managed to patch the security issue very quickly after its discovery. The company reported that it took less than 10 days to resolve the problem.
Q.What should users do if they are concerned their device might have been affected?
What should users do if they are concerned their device might have been affected?
Users concerned about the vulnerability should update their WhatsApp application to the latest version. Installing the update will make the attack inoperable, even if the device was previously infected.
Reader pulse
Does this vulnerability change your trust in messaging apps for business?
20,295 votes so far