Skip to main content / The bug, which has been patched in newer versions of the app, would let an attacker execute malicious code after sending a specially crafted video call Sep 27, 2022, 12:13 PM UTC| Illustration by Alex Castro / The VergeWhatsApp has published details of a “critical” vulnerability that has been patched in a newer version of the app but could still affect older installations that have not been updated.Details were disclosed in a September update of WhatsApp’s page on security advisories affecting the app and came to light on September 23rd.The critical bug would allow an attacker to exploit a code error known as an integer overflow, letting them execute their own code on a victim’s smartphone after sending a specially crafted video call. Remote code execution vulnerabilities are a key step in installing malware, spyware, or other malicious applications on a target system, as they give attackers a foot in the door that can be used to further compromise the machine using techniques like privilege escalation attacks.The recently disclosed vulnerability has been assigned the identification number CVE-2022-36934 in the national vulnerability database and given a severity score of 9.8 out of 10 on the CVE scale. This equates to the…
Read More











