Cisa Warns Of Whatsapp 0-day Vulnerability Exploited In Attacks

This month, the Biden administration said at least eight telecommunications infrastructure companies in the U.S., and possibly more, had been broken into by Chinese hackers. In the cloud, data is stored with a third-party provider and accessed over the internet. Organizations must understand the security posture of the cloud service provider in order to make sound decisions on using the service. “I find interaction-less bugs to be the most interesting class of vulnerabilities just because they’re so useful to attackers,” Silvanovich says. When someone calls you on an internet-based communication app, the system can start setting up the connection between your devices right away, a process known as “establishment,” so the call can start instantly when you hit accept.

Once added, the attacker gains real-time access to all future messages in that conversation. The encryption itself remains intact, but the attacker is now a legitimate participant in the chat. This is the equivalent of someone slipping into a secure boardroom meeting by stealing a badge, no need to crack the safe when the door is open. As communication tools become integral to business operations, data breaches involving communication tools can have far-reaching consequences for organizations and individuals.

Researchers

When developers skip origin validation or improperly handle message data, postMessage vulnerabilities can and will emerge. Before we move to the exploitation part, let’s first understand how we can identify potential postMessage vulnerabilities. PostMessage vulnerabilities arise when developers fail to properly validate message origins or sanitize content within cross-origin communication handlers. As modern web applications increasingly rely on the postMessage API for cross-origin communication, whether for embedded widgets, OAuth flows, third-party integrations, or iframe-based components, the attack surface continues to grow. That code, which many apps (including banking, social media, and SMS-ID authentication systems) use as a second layer of security , is the master key. Sharing it, even “because a friend asked for it,” is tantamount to handing over control of the account on a silver platter.

The Messaging App Landscape (2020–

  • While that may not be practical for every business, it’s a strong signal (no pun intended) that not all encrypted apps are created equal.
  • Look for places where message data is used in dangerous DOM sinks without proper validation, such as innerHTML, eval(), document.write(), or passed to other DOM manipulation methods.
  • However, under pressure, The Atlantic decided to publish the group’s full contents so that the public could assess the seriousness of the matter, also revealing disparaging remarks about European allies that had already surfaced at other summits.
  • When enabled, it tracks data flow from sources (including postMessage event handlers) to sinks, such as innerHTML, and alerts you when untrusted data reaches a dangerous location.
  • By indexing some test websites to Bing, we were able to extract their static tracking links and use them to bypass the url_safe check, allowing our links to be fully rendered.

The recent headlines about vulnerabilities in Signal, a messaging app long touted for its end-to-end encryption and privacy-first design, have sent ripples through the cybersecurity and communications worlds. For professionals in communications, marketing, and PR who rely on secure channels to manage sensitive conversations, these revelations are more than just technical footnotes. They raise urgent questions about how secure our “secure” tools really are, and what’s at stake when those tools fall short. And when even the most trusted platforms show cracks, the consequences stretch far beyond the IT department.

vulnerability in messaging

See Tenable In Action

Add Advanced Support for access to phone, community, and chat support 24 hours a day, 365 days a year. In addition to its long-term memory feature, ChatGPT considers the current conversation and context when responding. To avoid confusion, we will refer to this type of memory as Conversational Context. If the user asks it to remember something, or if there is some Meetwithmature review information that the engine deems important even without an explicit request, it can be remembered using memories.

To protect against this, if you receive an iMessage from someone who is not in your contacts, and with whom you’ve never exchanged messages, your iPhone automatically disables any links in the message. SMS and iMessages are commonly used by scammers to send links intended to carry out phishing attacks, and to attempt to instal malware in iPhones. The security flaws, which required little technical skill to exploit, have all since been patched. Additionally, CISA advises organizations to follow applicable Binding Operational Directive (BOD) guidance specifically related to cloud services security requirements.

Burp Suite DOM Invader is a browser extension built into Burp Suite’s embedded browser that automatically detects DOM-based vulnerabilities, including postMessage bugs. DOM Invader monitors postMessage traffic, identifies message handlers, and can automatically test for XSS by injecting canary values into messages. It highlights potentially dangerous sinks and provides a visual representation of message flows. Automated tooling will hook the message event listener and detect global postMessage calls.

However, end-user awareness campaigns remain critical, as smishing often bypasses technical defenses. In a statement shared with The Hacker News, WhatsApp said it sent in-app threat notifications to less than 200 users who may have been targeted as part of the campaign. Built for the modern attack surface, Nessus Expert enables you to see more and protect your organization from vulnerabilities from IT to the cloud.

If one team member’s desktop is compromised, the attacker now has access to the entire conversation thread. That includes draft statements, internal assessments, and real-time strategy adjustments. The fallout could be disastrous, not just in terms of the breach itself, but in how it undermines trust with clients, stakeholders, and the public. Below are a few free, open-source tools that can help test for DOM-based vulnerabilities, including postMessage bugs. Modern applications often minify and obfuscate their JavaScript as part of optimizing site traffic, making manual review challenging. To counter this, use your browser’s developer tools to format the code, or leverage third-party services that aim to make the code more readable.

Examining the code snippet above, we can notice that a postMessage call is defined on line 27 as part of an OAuth implementation. Additionally, we can also notice that the postMessage data includes the OAuth token, which may be exchanged for a session token later once it reaches the parent window. Inspecting the code snippet further, we can also see that one of the properties coming from the web message is passed to the location.href DOM sink on line 31.