#1 Middle East & Africa Trusted Cybersecurity News & Magazine |

30 C
Dubai
Monday, October 14, 2024
Cybercory Cybersecurity Magazine
HomeTopics 1Application SecurityWhatsApp Bug Exposes Flaw in ‘View Once’ Privacy Feature – Users Urged...

WhatsApp Bug Exposes Flaw in ‘View Once’ Privacy Feature – Users Urged to Be Cautious

Date:

Related stories

OpenAI Thwarts 20 Global Malicious Campaigns Using AI for Cybercrime and Disinformation

In an era where artificial intelligence (AI) is revolutionizing...

Hacker Attack Disrupts Russian State Media on Putin’s Birthday

On October 7, 2024, a significant cyberattack disrupted Russian...
spot_imgspot_imgspot_imgspot_img

WhatsApp, the world’s leading end-to-end encrypted messaging platform, is facing scrutiny following the discovery of a significant bug that undermines its “View Once” privacy feature. Introduced in 2021, this feature was designed to enhance user privacy by allowing pictures and videos to disappear after being viewed once. However, a newly uncovered vulnerability in WhatsApp’s web application enables malicious users to bypass this function and retain content that was intended to vanish after a single view.

Details of the Vulnerability

The “View Once” feature on WhatsApp was developed to work exclusively on mobile applications for Android and iOS, warning users who attempt to open “View Once” media on WhatsApp Web or Desktop that they need to switch to their mobile devices. Unfortunately, Tal Be’ery, a cybersecurity researcher and CTO of crypto wallet company Zengo, discovered a critical flaw in WhatsApp’s web app that allows any recipient to bypass the “View Once” restriction.

Be’ery, who has been delving into WhatsApp’s privacy vulnerabilities for several months, published a blog post on September 9, 2024, highlighting this flaw. According to Be’ery, the bug permits malicious users to view and save “View Once” media without triggering the intended privacy safeguards. During a live demonstration for TechCrunch, Be’ery successfully captured and saved a “View Once” picture sent to him via WhatsApp Web.

“The only thing worse than no privacy is a false sense of privacy,” Be’ery noted in his blog post. He expressed concerns that users are misled into believing their communication is secure when it isn’t. “WhatsApp’s ‘View Once’ is a blunt form of false privacy and should either be thoroughly fixed or abandoned,” he added.

Be’ery reported the bug to Meta, WhatsApp’s parent company, through its bug bounty platform on August 26, 2024. In response to TechCrunch’s inquiry, WhatsApp spokesperson Zade Alsawah acknowledged the issue and stated, “We are already in the process of rolling out updates to View Once on web. We continue to encourage users to only send View Once messages to people they know and trust.” However, the company has not provided a specific timeline for when the fix will be fully deployed.

It is worth noting that Be’ery is not the first to identify this loophole. TechCrunch has identified numerous browser extensions that make bypassing the “View Once” feature on WhatsApp Web trivially easy. There have also been active discussions on various social media platforms outlining methods to exploit this vulnerability, amplifying the potential risk.

10 Tips to Avoid Such Threats in the Future

  1. Use Trusted Devices Only: Always use WhatsApp on mobile devices to ensure “View Once” messages work as intended.
  2. Verify Recipients: Only send sensitive media to people you know and trust. Avoid sending “View Once” messages to unknown or unverified contacts.
  3. Be Aware of Privacy Limitations: Understand that even features meant for privacy can have vulnerabilities. Remain cautious with sensitive content.
  4. Update WhatsApp Regularly: Ensure you are using the latest version of WhatsApp on all your devices to get the most recent security patches and updates.
  5. Avoid Clicking on Suspicious Links: Never click on links from unknown sources, which could lead to browser extensions designed to bypass WhatsApp’s security.
  6. Disable WhatsApp Web if Not in Use: If you do not need to use WhatsApp on the web, consider disabling it to minimize the risk of potential exploits.
  7. Use Additional Encryption Tools: Consider using additional encryption tools or apps that provide higher privacy and security for extremely sensitive content.
  8. Stay Informed About Security Updates: Follow security news and updates from reputable sources like TechCrunch to stay informed about any newly discovered vulnerabilities.
  9. Participate in Security Awareness Programs: Regularly engage in cybersecurity training to learn about emerging threats and how to protect yourself online.
  10. Report Suspicious Activity: Immediately report any suspicious activities or potential security vulnerabilities to WhatsApp or relevant authorities.

Conclusion

The recent discovery of a vulnerability in WhatsApp’s “View Once” feature serves as a stark reminder of the limitations of digital privacy tools. While WhatsApp works on rolling out updates to address this issue, users must remain vigilant and cautious. As cyber threats evolve, so must our understanding of the potential risks associated with digital communication platforms. Staying informed, cautious, and proactive is key to maintaining personal privacy and security in today’s interconnected world.

Source: Techcrunch

Want to stay on top of cybersecurity news? Follow us on Facebook – X (Twitter) – Instagram – LinkedIn – for the latest threats, insights, and updates!

Ouaissou DEMBELE
Ouaissou DEMBELEhttps://cybercory.com
Ouaissou DEMBELE is an accomplished cybersecurity professional and the Editor-In-Chief of cybercory.com. He has over 10 years of experience in the field, with a particular focus on Ethical Hacking, Data Security & GRC. Currently, Ouaissou serves as the Co-founder & Chief Information Security Officer (CISO) at Saintynet, a leading provider of IT solutions and services. In this role, he is responsible for managing the company's cybersecurity strategy, ensuring compliance with relevant regulations, and identifying and mitigating potential threats, as well as helping the company customers for better & long term cybersecurity strategy. Prior to his work at Saintynet, Ouaissou held various positions in the IT industry, including as a consultant. He has also served as a speaker and trainer at industry conferences and events, sharing his expertise and insights with fellow professionals. Ouaissou holds a number of certifications in cybersecurity, including the Cisco Certified Network Professional - Security (CCNP Security) and the Certified Ethical Hacker (CEH), ITIL. With his wealth of experience and knowledge, Ouaissou is a valuable member of the cybercory team and a trusted advisor to clients seeking to enhance their cybersecurity posture.

Subscribe

- Never miss a story with notifications

- Gain full access to our premium content

- Browse free from up to 5 devices at once

Latest stories

spot_imgspot_imgspot_imgspot_img

LEAVE A REPLY

Please enter your comment!
Please enter your name here