WhatsApp alert – Fans will be shocked by this threat and why it’s not been fixed

With over 1.5billion users, WhatsApp continues to be the most popular messaging service on the planet.

But with so many people accessing this service it makes it a prime target for hackers and cybercriminals intent on stealing personal data.

WhatsApp is considered to be a very secure platform but a recent discovery by the team at Check Point Research will certainly have users concerned.

The cybersecurity experts have found a flaw which could allow cyber attackers to intercept and manipulate messages sent in both private and group conversations.

According to the firm, they revealed some of these vulnerabilities to the Facebook-owned app late last year but the problem still appears to exist.

In a post on its blog, Check Point Research said: “Following the process of Responsible Disclosure, Check Point Research informed WhatsApp of its findings. From Check Point Research’s perspective, we believe these vulnerabilities to be of the utmost importance and require attention.

“To demonstrate the severity of this vulnerability in WhatsApp, we created a tool that allows us to decrypt WhatsApp communication and spoof the messages.

“As is well-known, WhatsApp encrypts every message, picture, call, video or any other type of content you send so that only the recipient can see it. WhatsApp does not have the ability to view these messages.”

One of the reasons this issue is so serious is that, if exploited, it could give attackers the power to create and spread misinformation from what appear to be trusted sources.

Speaking about the issues at the Black Hat cyber-security conference in Las Vegas, researcher Oded Vanunu told the BBC: “It’s a vulnerability that allows a malicious user to create fake news and create fraud.

“You can completely change what someone says.

“You can completely manipulate every character in the quote.”

There’s no word from Facebook on why these issues haven’t been addressed although WhatsApp has fixed one vulnerability which enabled threat actors to send a private message to another group participant disguised as a public message for all.

Source: Read Full Article