Crisis averted: WhatsApp fixed a lethal security flaw

It was hiding in plain sight.
 By 
Rachel Kraus
 on 
Original image replaced with Mashable logo
Original image has been replaced. Credit: Mashable

Imagine the app that is your communication lifeline unexpectedly and repeatedly dying.

The research arm of Check Point Security announced Tuesday that it found a WhatsApp vulnerability that could have caused frustrating and potentially disastrous functionality for users. The firm alerted WhatsApp to the problem in August, and it is now fixed.

Using group chat, Check Point was able to create an exploit that would repeatedly crash the app. WhatsApp wouldn't work again until the app was uninstalled, reinstalled, and the offending group chat was deleted. Here's a video demo of how it works.


You May Also Like

To most users, the bug might sound like just a frustrating experience. But the researchers pointed out to Fast Company that for users like activists or dissidents, it could be especially harmful: The bug has the potential to interrupt communication, and would require deletion of chat logs, multimedia, and contacts in group chats. That scenario is a real possibility, considering WhatsApp is a favored communication tool, especially internationally, since it has end-to-end encryption.

WhatsApp recently made changes to group chats to make them more secure and less susceptible to being a channel for spreading false and dangerous information. Before April of this year, anyone could add you to a group chat. Now, if you enable the setting, anyone can "invite" you to join a chat — but you have to accept or deny the invitation. Still, if you don't have your privacy specifically set to disallow group adding, anyone can simply add you to a group; groups can contain up to 256 people.

WhatsApp has been the target of vulnerability exploits before. This spring, attackers started manipulating WhatsApp to totally take control over users' phones using Pegasus spyware. And in 2018, Check Point discovered that it could manipulate the sender names and text of forwarded messages, which enabled the spread of fake news.

Facebook-owned WhatsApp has been taking action itself to combat fake news on WhatsApp by restricting the forwarding functionality. Despite fixes meant to make WhatsApp a tool for non-malicious communication, the work of these researchers show that the "secure" messaging platform is far from airtight.

Mashable Image
Rachel Kraus

Rachel Kraus is a Mashable Tech Reporter specializing in health and wellness. She is an LA native, NYU j-school graduate, and writes cultural commentary across the internetz.

Mashable Potato

Recommended For You
'Pretty Lethal' review: Ballerinas versus the Hungarian mob? Sure, why not.
Avantika, Laura Condor, Maddie Ziegler, Millicent Simmonds, and Iris Apatow star in "Pretty Lethal."

Meta can read your WhatsApp messages, lawsuit alleges
whatsapp logo

Updating your security mindset: Keep your data private and your devices secure
By PCMag
Cyber Security

Clawdbot AI security risks you need to know before trying it
Two digitally animated hands.

Homeland security pushes social media giants to dox anonymous accounts critical of ICE
By Jack Dawes
Ice Police Law Enforcement - Department of Homeland Security, Immigration and Customs Agents - stock photo

Trending on Mashable
NYT Connections hints today: Clues, answers for April 3, 2026
Connections game on a smartphone

Wordle today: Answer, hints for April 3, 2026
Wordle game on a smartphone

Google launches Gemma 4, a new open-source model: How to try it
Google Gemma

NYT Strands hints, answers for April 3, 2026
A game being played on a smartphone.

What's new to streaming this week? (April 3, 2026)
A composite of images from film and TV streaming this week.
The biggest stories of the day delivered to your inbox.
These newsletters may contain advertising, deals, or affiliate links. By clicking Subscribe, you confirm you are 16+ and agree to our Terms of Use and Privacy Policy.
Thanks for signing up. See you at your inbox!