ZeroHour
Security Affairspublished ()ingested @securityaffairs

FB fixed a WhatsApp bug that allowed hackers to access local file system

criticalVulnerabilityimportance 60CVE-2019-18426

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2019-18426
Cross-Site Scripting and Local File Read in WhatsApp Desktop

CVE-2019-18426 is a cross-site scripting flaw (CWE-79) in WhatsApp Desktop versions prior to 0.3.9309 which, when the desktop client is paired with WhatsApp for iPhone versions prior to 2.20.10, also permits reading local files on the machine running the desktop app. It is triggered when the victim clicks a link preview generated from a specially crafted text message, requiring no privileges but user interaction (CVSS 3.1: 8.2, AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N). Successful exploitation runs attacker-controlled content in the desktop app's context, breaking out of the chat boundary and giving the attacker access to files on the victim's computer. Users running WhatsApp Desktop paired with an iPhone are affected, and Meta (then Facebook) remediated the flaw in WhatsApp Desktop 0.3.9309 and WhatsApp for iPhone 2.20.10. The bug is listed in CISA's Known Exploited Vulnerabilities catalog (added 2022-05-23), has a public proof-of-concept, and carries an EPSS score of 67.9% probability of exploitation within 30 days (99th percentile), indicating significant exploitation risk.

Do: Update WhatsApp Desktop to version 0.3.9309 or later and WhatsApp for iPhone to version 2.20.10 or later, per vendor instructions. Inventory endpoints running the WhatsApp Desktop client and verify the versions of both the desktop app and the paired iPhone app, since the CISA KEV listing confirms active exploitation. Until patched, avoid clicking link previews from untrusted senders in WhatsApp Desktop.

8.268% KEV PoC
  • Meta Platforms WhatsApp Desktop prior to 0.3.9309
  • Meta Platforms WhatsApp for iPhone prior to 2.20.10 (when paired with vulnerable WhatsApp Desktop)
masstens of millions of desktop users (WhatsApp has a 2B+ user base; fully vulnerable pairings now rare due to auto-updates)
Full article298 words · extracted from securityaffairs.com · click to collapse

Pierluigi Paganini February 04, 2020

Facebook addressed a critical issue in WhatsApp that would have allowed attackers to read files from a user’s local file system, on macOS and Windows.

Facebook has addressed a critical vulnerability in WhatsApp, tracked as CVE-2019-18426, that would have allowed hackers to read files from a user’s local file system, on macOS and Windows systems.

“A vulnerability in WhatsApp Desktop when paired with WhatsApp for iPhone allows cross-site scripting and local file reading. Exploiting the vulnerability requires the victim to click a link preview from a specially crafted text message.” reads the security advisory published by Facebook.

The issue could be exploited by a remote attacker by tricking the victims into clicking a link preview from a specially crafted text message.

The CVE-2019-18426 flaw affects WhatsApp Desktop prior to v0.3.9309 paired with WhatsApp for iPhone versions prior to 2.20.1.: 01-21-2020

The vulnerability received an 8.2 high severity CVSS 3.x base score, it was discovered by Gal Weizman from PerimeterX.

Weizman discovered a gap in WhatsApp’s Content Security Policy (CSP) that allowed for cross-site scripting (XSS) on the desktop app, further analysis allowed the expert to gain read permissions on the local file system on both Windows and macOS WhatsApp desktop apps.

“if you run an old version of a vulnerable app, one can exploit that vulnerability and do bad things to you.” wrote the expert.

“I did however demonstrated how I use fetch() API, for example, to read files from the local OS like the content of C:\Windows\System32\drivers\etc\hosts file in this case,”

The flaw could have allowed attackers to inject malicious code and links within messages sent that would be completely transparent to the victims.

[adrotate banner=”9″] [adrotate banner=”12″]

Pierluigi Paganini

(SecurityAffairs – United Nations, hacking)

[adrotate banner=”5″]

[adrotate banner=”13″]



Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/97331/hacking/whatsapp-bug-fixed.html