WhatsApp, Telegram Patch File-Upload Bug

whatsapp-telegram-patch-fileupload-bug photo 1

A web server vulnerability could have let hackers hijack the accounts of Telegram and WhatsApp users, security experts disclosed on Wednesday.

The messaging services are popular for their security features, including end-to-end encryption that protects data sent via their smartphone apps. But that end-to-end encryption may have actually made the web versions of Telegram and WhatsApp more vulnerable, according to researchers from Check Point Security, making it relatively easy for hackers to access personal data.

The loophole, which has since been fixed, involved the file-upload tools on the websites of both services. By uploading a malicious document (and, in WhatsApp's case, disguising it with a legitimate preview image), Check Point researchers were able to bypass security safeguards and gain access to the services' user data.

"Since messages were encrypted without being validated first, WhatsApp and Telegram were blind to the content, thus making them unable to prevent malicious content from being sent," Check Point researchers wrote in a blog post. No hacks are believed to have used this loophole, although Check Point said the danger was very real.

"This vulnerability, if exploited, would have allowed attackers to completely take over users' accounts on any browser, and access victims' personal and group conversations, photos, videos and other shared files, contact lists, and more," the researchers wrote. "This means that attackers could potentially download your photos and or post them online, send messages on your behalf, demand ransom, and even take over your friends' accounts."

Related

  • Confide Secure Messaging App Patches Critical BugsConfide Secure Messaging App Patches Critical Bugs

Check Point said it disclosed the loophole to WhatsApp's and Telegram's security teams on March 7, and both companies acknowledged the issue and have since developed a fix for their web clients.

That fix is relatively simple: both services now validate files attached to messages before they're encrypted. If you send files or messages via the WhatsApp or Telegram websites, all you need to do is make sure that you restart your browser to make sure they're accessing the latest version of the services' web clients.

Security experts have questioned Telegram's protections before, including in 2015, when unencrypted copies of the messages sent using the app's Secret Chat tool were found on Android devices.

Recommended stories

Skype Is Awful for Text Chat. Use Telegram Instead

Skype is more than just voice and video chat: it contains text chat, too. Unfortunately, it’s incredibly unreliable, and only getting worse. None of my friends use it anymore–everyone’s switched to Telegram, which always works properly. Microsoft has wasted its time by rewriting the Skype client

Relax WhatsApp, Telegram Patch File-Upload Bug stories

6 ways to delete yourself from the internet

Finally ready to get off the grid? It's not quite as simple as it should be, but here are a few easy-to-follow steps that will point you in the right direction at the very least.

How to Hack Wi-Fi Passwords

Your intensions when cracking a Wi-Fi password are no doubt noble—we trust you—so here's how to do it.

More stories

Twitter Accounts Hijacked by Nazi Spam

Third-party tool Twitter Counter was hacked, allowing the scammers to post on the Twitter timelines of those who had linked their account to the service.