Critical WhatsApp Spyware Flaw Patched Amid Global Surveillance Fears

A severe WhatsApp vulnerability allows attackers to install spyware through missed calls, putting billions of users at risk. Facebook releases an urgent patch to block the exploit allegedly linked to the NSO Group.

A critical security flaw in WhatsApp puts 1.5 billion users at risk of spyware attacks. The vulnerability exists in the WhatsApp VOIP stack and allows remote code execution through specially crafted SRTCP packets. Attackers exploit this weakness by simply placing a WhatsApp call to a target device, requiring no action from the recipient.

The spyware successfully installs even if the victim does not answer the call, and the malicious call subsequently disappears from the device logs. Reports indicate that this sophisticated exploit originates from the Israeli NSO Group, a firm known for selling advanced surveillance software. NSO Group denies involvement in this specific attack despite their controversial history.

Facebook addresses this severe issue by releasing an updated version of WhatsApp for all devices. Security researchers emphasize that this type of attack requires extensive reverse engineering and deep knowledge of the application's code. Users must immediately update their WhatsApp application to the latest version to protect their devices from potential infection.

Read More at the original source →