Skip to main content

WhatsApp flaw could have let hackers take control of a phone via an MP4 file

Have you received a strange MP4 file on WhatsApp recently? It’s probably best to avoid downloading it — at least until you update to the latest version. WhatsApp recently fixed a vulnerability that could have allowed hackers to send a specially coded MP4 file, and then remotely take control of a phone and access the messages and files stored on that device.

The flaw is known as CVE-2019-11931, and it affected Android devices with WhatsApp versions before 2.19.274, and iPhones with WhatsApp versions before 2.19.100. Currently, there doesn’t seem to be any indication that the flaw was actually exploited. Facebook, which owns WhatsApp, says the issue was discovered internally — not through any known attacks or a third-party security researcher.

Recommended Videos

“WhatsApp is constantly working to improve the security of our service. We make public reports on potential issues we have fixed consistent with industry best practices,” said a Facebook spokesperson in a statement to The Hacker News. “In this instance, there is no reason to believe that users were impacted.”

There isn’t much extra information about the vulnerability or how it works, but as long as users update to the latest version of WhatsApp, they shouldn’t have any issues.

Recently, WhatsApp sued Israeli mobile surveillance company NSO Group over an exploit that was used to attack hundreds of different phones. These included the likes of human rights defenders, journalists, and more. This particular attack disguised malicious code as call settings, and allowed the attackers to deliver code to phones as if it came from WhatsApp’s servers. Once the initial code was delivered, attackers were able to inject more malicious code into a device’s memory. In total, 1,400 devices were affected.

In general, it’s recommended to ensure that all your apps are kept up to date, so as to make sure that any security issues are patched. There are other things you can do to ensure that your phone remains uncompromised. For example, if you have an Android phone, you can make sure to only download apps from the Google Play Store. It’s also important to always make sure that your version of Android or iOS is the latest version — especially considering the fact that security vulnerabilities often exist in the operating system.

Christian de Looper
Christian de Looper is a long-time freelance writer who has covered every facet of the consumer tech and electric vehicle…
What is WhatsApp? How to use the app, tips, tricks, and more
WhatsApp logo on a phone.

There’s been no shortage of instant messaging apps over the past decade, as the rise of advanced smartphone platforms has created the need for more sophisticated ways to communicate than traditional SMS text messages allowed for.

In fact, the Apple App Store and Google Play Store are both littered with apps that promised to be the next big thing in mobile communications. Yet, many of those fell by the wayside as they failed to achieve the critical mass of users needed to make them useful. After all, apps designed for communicating with others don’t do you much good unless enough folks are using them. Luckily, WhatsApp made our list of the best iPhone Apps and our infamous list of the best Android apps out there.

Read more
You’ll soon be able to use WhatsApp on more than one phone
Two phones on a table next to each other. One is showing the WhatsApp logo, and the other is running the WhatsApp application.

WhatsApp, one of the most used messaging services in Europe and parts of Asia, is about to close a major flaw. As spotted by the sleuths over on WABetainfo, the company is planning an update that will allow the use of a secondary device -- including another phone or tablet. Currently, WhatsApp only allows phone users to link their account via its web or desktop clients.

The new feature is dubbed companion mode. Once it rolls out, you'll have a workflow that's quite similar to setting up WhatsApp Web or WhatsApp on the desktop. Rather than entering a number, you'll be able to scan a QR code with your main phone to log in to your existing WhatsApp account.

Read more
WhatsApp is copying two of Zoom’s best video-calling features
Call Links by WhatsApp

WhatsApp is taking a couple of pages out of Zoom's playbook. The Meta-owned company is rolling out the Call Links feature, making it easier for people to join audio and video calls with just one tap on the phone screen.

Mark Zuckerberg announced the new feature in a Facebook post on Monday morning. Starting this week, WhatsApp users will be able to tap the Call Links option within the Calls tab and create a link for audio or video calls to send to their friends and family, who will then tap on the link and join the call from there.

Read more