Article Details

Scrape Timestamp (UTC): 2024-10-16 04:32:22.230

Source: https://www.theregister.com/2024/10/16/whatsapp_privacy_concerns/

Original Article Text

Click to Toggle View

WhatsApp may expose the OS you use to run it – which could expose you to crooks. Messaging service creates persistent user IDs that have different qualities on each device. An analysis of Meta's WhatsApp messaging software reveals that it may expose which operating system a user is running, and their device setup information – including the number of linked devices. That analysis comes from security researchers at cryptocurrency wallet maker Zengo, who previously found a security weakness in the app's View Once feature – and now claim they’ve found another flaw. The issue stems from how the application manages its multi-device setup, and the metadata it broadcasts during communication. "We found out that different implementations of WhatsApp generate that message ID in a different manner, which allows us to fingerprint them to know if it's coming from Windows," Zengo cofounder Tal Be'ery told The Register. In an explainer, Be'ery detailed how each device linked to a WhatsApp account – whether it's web, macOS, Android, iPhone, or Windows – is assigned a unique and persistent identity key. The qualities of those keys vary for each OS on which WhatsApp runs: a 32-character ID is created for Android devices, iPhones use a 20-character prefix that is preceded four additional characters, while the WhatsApp desktop app for Windows uses an 18-character ID. The different qualities of IDs for different platforms, Be’ery argues, mean someone trying to spread malware through WhatsApp could identify users' operating system and target them accordingly. "It's not the end of the world," he assured. "But when you send malware to a device it's really, really important to know which operating system it runs on, because you have different vulnerabilities and different exploits." A clever attacker could even look at all IDs associated with a user, figure out all the OSes on which they access WhatsApp, and choose the most vulnerable one to attack, Be'ery suggested. He noted that Meta had been alerted to the problem and acknowledged the finding on September 17. But since then, the security team at Zengo has heard nothing in response. "It's fairly easy to comprehend," he explained – adding that in the absence of any response, Zengo was taking the issue public. WhatsApp had no comment at the time of going to press.

Daily Brief Summary

CYBERCRIME // WhatsApp Flaw Exposes User OS, Heightening Malware Risk

Security researchers at Zengo discovered a new flaw in WhatsApp revealing users' operating system and device setup.

The issue arises from the unique and persistent identity keys assigned to each device using WhatsApp, varying by operating system.

This vulnerability allows cybercriminals to identify the operating system of a user, enabling targeted malware attacks.

Specific identity key formats for different platforms like Android, iOS, and Windows facilitate this OS fingerprinting.

Tal Be’ery from Zengo emphasized the potential for attackers to exploit the most vulnerable system accessed by a victim’s WhatsApp.

Meta was informed about this security flaw on September 17, but has not responded to Zengo since the initial acknowledgment.

Zengo has decided to go public with this information due to the lack of response from Meta’s security team regarding the flaw.

WhatsApp has not provided any comments on the matter.