WhatsApp discloses critical bug in older versions, now patched - New Delhi News
by IANS | Updated Sep 27, 2022
The vulnerability could allow an attacker to exploit a code error known as an integer overflow.
"An integer overflow in WhatsApp for Android prior to v18.104.22.168, Business for Android prior to v22.214.171.124, iOS prior to v126.96.36.199, Business for iOS prior to v188.8.131.52 could result in remote code execution in an established video call," WhatsApp said in an update.
In remote code execution, a hacker can remotely execute commands on someone else's computing device.
Remote code executions (RCEs) usually occur due to malicious malware downloaded by the host and can happen regardless of the device's geographic location.
The recently disclosed vulnerability has been called CVE-2022-36934, with a severity score of 9.8 out of 10 on the CVE scale.
WhatsApp also revealed details of another bug that could have caused remote code execution when receiving a crafted video file.
Both of these vulnerabilities have been patched in the latest versions of WhatsApp.
WhatsApp on Monday announced it was rolling out Call Links to make it easier to start and join a call in just one tap.
The company also started testing secured and encrypted group video calls for up to 32 people on WhatsApp.