WhatsApp Voice Calls Exploited to Install Spyware Without User Action
A sophisticated cyber actor infects mobile phones with spyware through missed WhatsApp voice calls, requiring no action from the user. WhatsApp quickly patches the vulnerability and urges all users to update their apps immediately.
A sophisticated cyber actor infects mobile phones with highly advanced spyware through missed WhatsApp voice calls, requiring absolutely no action from the targeted user. The malware penetrates the device silently during the calling process, allowing the attackers to take over the mobile operating system completely. WhatsApp discovers this severe security flaw in early May while engineers work on additional security enhancements for the voice calling feature.
Reports identify the Israel-based NSO Group as the creator of this surveillance tool, a company known for selling spyware to various governments and intelligence agencies. The attack targets a wide range of devices, including iPhones, Android phones, Microsoft Windows phones, and Samsung's Tizen system. Security researchers from Citizen Lab describe the hack as a very scary vulnerability because there is nothing a user can do to prevent it short of uninstalling the application entirely.
WhatsApp, which serves over 1.5 billion users globally, responds swiftly by contacting human rights groups, fixing the underlying issue, and pushing out a software patch. The company urges all users to upgrade to the latest version of the application and keep their mobile operating systems up to date to protect against potential targeted exploits. This proactive measure aims to secure devices against further unauthorized access through this alarming zero-day vulnerability.