A security vulnerability in popular messaging app WhatsApp’s image filter function discovered by Check Point Research could have exploited more than two billion users worldwide if left unpatched. It is estimated more than 55 billion messages are being sent daily over WhatsApp, with 4.5 billion photos and one billion videos shared per day. Check Point Research recommends for WhatsApp users to always keep their apps and operating systems updated. Image Filter Function According toe CPR, the vulnerability was rooted in WhatsApp’s image filter function. Image filtering is a process through which pixels of the original image are modified to achieve some visual effects, such as blur or sharpen. During their research study, CPR learned that switching between various filters on crafted GIF files indeed caused WhatsApp to crash. CPR identified one of the crashes as a memory corruption. CPR promptly reported the problem to WhatsApp, who named for the vulnerability CVE-2020-1910, detailing it as an out-of-bounds read and write issue. Successful exploitation of the vulnerability would have required an attacker to apply specific image filters to a specially crafted image and send the resulting image. Coordinated Disclosure CPR disclosed its findings to WhatsApp on November 10, 2020. WhatsApp verified and acknowledged the…
Read More











