Critical WhatsApp Bugs Could Have Let Attackers Hack Devices Remotel

Share:

WhatsApp has released security updates to address two flaws in its messaging app for Android and iOS that could lead to remote code execution on vulnerable devices.

One of them concerns CVE-2022-36934 (CVSS score: 9.8), a critical integer overflow vulnerability in WhatsApp that results in the execution of arbitrary code simply by establishing a video call.

The issue impacts the WhatsApp and WhatsApp Business for Android and iOS prior to versions 2.22.16.12.

 

Also patched by the Meta-owned messaging platform is an integer underflow bug, which refers to an opposite category of errors that occur when the result of an operation is too small for storing the value within the allocated memory space.

The high-severity issue, given the CVE identifier CVE-2022-27492 (CVSS score: 7.8), affects WhatsApp for Android prior to versions 2.22.16.2 and WhatsApp for iOS version 2.22.15.9, and could be triggered upon receiving a specially crafted video file.

Exploiting integer overflows and underflows are a stepping stone towards inducing undesirable behavior, causing unexpected crashes, memory corruption, and code execution.

 

WhatsApp did not share more specifics on the vulnerabilities, but cybersecurity firm Malwarebytes said that they reside in two components called Video Call Handler and Video File Handler, which could permit an attacker to seize shoppingmode control of the app.

A spokesperson for WhatsApp told The Hacker News that “we discovered [the flaws] ourselves and there was no evidence of exploitation.”

Vulnerabilities on WhatsApp can be a lucrative attack vector for threat actors looking to plant malicious software on compromised devices. In 2019, an audio calling flaw was exploited by the Israeli spyware maker NSO Group to inject the Pegasus spyware.

https://thehackernews.com/2022/09/critical-whatsapp-bugs-could-have-let.html

Leave a Comment

Your email address will not be published. Required fields are marked *

loader-image
London, GB
3:18 pm, May 18, 2025
weather icon 17°C
L: 15° | H: 18°
few clouds
Humidity: 56 %
Pressure: 1019 mb
Wind: 1 mph ENE
Wind Gust: 3 mph
UV Index: 0
Precipitation: 0 mm
Clouds: 13%
Rain Chance: 0%
Visibility: 10 km
Sunrise: 5:04 am
Sunset: 8:49 pm
DailyHourly
Daily ForecastHourly Forecast
Today 10:00 pm
weather icon
15° | 18°°C 0 mm 0% 7 mph 63 % 1020 mb 0 mm/h
Tomorrow 10:00 pm
weather icon
11° | 18°°C 0 mm 0% 11 mph 82 % 1022 mb 0 mm/h
Tue May 20 10:00 pm
weather icon
9° | 20°°C 0 mm 0% 8 mph 79 % 1022 mb 0 mm/h
Wed May 21 10:00 pm
weather icon
12° | 18°°C 1 mm 100% 9 mph 93 % 1019 mb 0 mm/h
Thu May 22 10:00 pm
weather icon
9° | 17°°C 0 mm 0% 10 mph 63 % 1023 mb 0 mm/h
Today 4:00 pm
weather icon
17° | 17°°C 0 mm 0% 7 mph 57 % 1019 mb 0 mm/h
Today 7:00 pm
weather icon
17° | 17°°C 0 mm 0% 6 mph 55 % 1019 mb 0 mm/h
Today 10:00 pm
weather icon
13° | 14°°C 0 mm 0% 6 mph 63 % 1020 mb 0 mm/h
Tomorrow 1:00 am
weather icon
12° | 12°°C 0 mm 0% 7 mph 69 % 1020 mb 0 mm/h
Tomorrow 4:00 am
weather icon
11° | 11°°C 0 mm 0% 6 mph 82 % 1020 mb 0 mm/h
Tomorrow 7:00 am
weather icon
12° | 12°°C 0 mm 0% 7 mph 73 % 1021 mb 0 mm/h
Tomorrow 10:00 am
weather icon
16° | 16°°C 0 mm 0% 8 mph 51 % 1021 mb 0 mm/h
Tomorrow 1:00 pm
weather icon
18° | 18°°C 0 mm 0% 10 mph 45 % 1021 mb 0 mm/h
Name Price24H (%)
Bitcoin(BTC)
€93,656.45
1.65%
Ethereum(ETH)
€2,266.00
2.70%
Tether(USDT)
€0.90
-0.01%
XRP(XRP)
€2.16
3.18%
Solana(SOL)
€154.73
3.55%
USDC(USDC)
€0.90
0.00%
Dogecoin(DOGE)
€0.201890
5.51%
Shiba Inu(SHIB)
€0.000013
5.68%
Pepe(PEPE)
€0.000012
9.16%
Peanut the Squirrel(PNUT)
€0.312764
17.62%
Scroll to Top