Meta has begun the rollout of fixes for several zero-day vulnerabilities impacting WhatsApp, which could be exploited to facilitate user metadata exposure, reports SecurityWeek.Multiple WhatsApp zero-days could allow the fingerprinting of targeted devices' operating system before the subsequent deployment of illicit payloads, including spyware, according to researchers. While Meta has already acknowledged the issue, the device fingerprinting technique persists, said Zengo co-founder and Chief Technology Officer Tal Be'ery."Attackers can still distinguish with high certainty between Android and iPhone based on One-Time PK ID... However, it seems reasonable to believe that this is WhatsApp's first step toward a more complete fix that will make these fields random on all operating systems and platforms. If indeed this is the plan, it will obliterate this fingerprinting privacy vulnerability," said Be'ery, who also criticized Meta's silent release of remediation measures. Meanwhile, WhatsApp has expressed its commitment to bolstering its app security, as it downplayed OS inference to have a minimal security impact.
Application security, Data Security, Vulnerability Management

Fixes underway for metadata-leaking WhatsApp bugs
(Adobe Stock)

Related Events
Get daily email updates
SC Media's daily must-read of the most current and pressing daily news
You can skip this ad in 5 seconds
