WhatsApp Bug Could Let Attackers Crash the App, Delete Group Messages: Check Point

WhatsApp users who haven’t updated their Android app since the middle of September are advised to install the latest version.

Advertisement
By Jagmeet Singh | Updated: 17 December 2019 19:24 IST
Highlights
  • WhatsApp bug was discovered by Check Point Research in August
  • Users wouldn’t be able to restore their group conversation
  • WhatsApp Web would be used to cause crash loop
WhatsApp Bug Could Let Attackers Crash the App, Delete Group Messages: Check Point

WhatsApp rolled out an update in September to fix the bug

WhatsApp has fixed a bug that could have allowed attackers to deliver a malicious group message to repeatedly crash the app for all the members of the group, a report by Check Point Research revealed on Tuesday. The bug, which was discovered in August, is said to have the potential to cause a crash loop that could only be fixed by completely uninstall and reinstall the app. Even after reinstalling, users wouldn't be able to return to the affected group and hence would lose all the messages and media content exchanged in that particular group.

According to the blog post by Check Point Research detailing the bug, an attacker would need to be a member of the target WhatsApp group to impact its other members. The instant messaging app has a limit of 256 members per group, which isn't too small to make room for a bad actor.

Once they have gained membership, the bad actor would need to use WhatsApp Web and debugging tool like Google Chrome's DevTools to edit specific message parameters that cause the crash loop for all group members.

The bug was found by the Check Point Research team after inspecting the communications between WhatsApp and WhatsApp Web. The researchers were able to manipulate the parameters used for WhatsApp communications that could cause repeated crash. Furthermore, technical details of the bug have been published in the blog post.

Advertisement

Although the affected users would be able to fix the crash loop by reinstalling WhatsApp on their devices, the bug forces them to delete the group that removes all its messages and media content.

“Because WhatsApp is one of the world's leading communication channels for consumers, businesses and government agencies, the ability to stop people using WhatsApp and delete valuable information from group chats is a powerful weapon for bad actors,” said Oded Vanunu, Check Point's Head of Product Vulnerability Research, in a media statement.

Advertisement

Check Point Research disclosed its findings to the WhatsApp bug bounty programme on August 28. WhatsApp has fixed the flaw starting its Android version number 2.19.58. Moreover, users, especially those who haven't updated WhatsApp since the middle of September, are recommended to download the latest version to prevent instances of crashes through malicious group messages.

“WhatsApp greatly values the work of the technology community to help us maintain strong security for our users globally,” said WhatsApp Software Engineer Ehren Kret. “Thanks to the responsible submission from Check Point to our bug bounty program, we quickly resolved this issue for all WhatsApp apps in mid-September. We have also recently added new controls to prevent people from being added to unwanted groups to avoid communication with untrusted parties all together.”

Advertisement

The latest fix comes weeks after WhatsApp was found to include an MP4 file security flaw that could be used to trigger remote code execution (RCE) or denial-of-service (DoS) attacks. The Facebook-owned app also in September fixed a bug that could let attackers steal user data directly through a malicious GIF file.

WhatsApp has a strong base of over 1.5 billion users across the globe -- with more than 400 million users in India alone. This gives a significant reason to researchers to actively dig in and find new vulnerabilities.

 

For the latest tech news and reviews, follow Gadgets 360 on X, Facebook, WhatsApp, Threads and Google News. For the latest videos on gadgets and tech, subscribe to our YouTube channel. If you want to know everything about top influencers, follow our in-house Who'sThat360 on Instagram and YouTube.

Advertisement

Related Stories

Popular Mobile Brands
  1. Apple Announces iOS 26 With Liquid Glass Design, These New Features
  2. Motorola Edge 60 With 5,500mAh Battery Launched in India: Price, Offers
  3. ChatGPT Down: Users Report Problems While Generating Responses
  4. iOS 26, iPadOS 26 Are Compatible With These iPhone and iPad Models
  5. Everything We Know About the Vivo T4 Ultra Ahead of Its June 11 Launch
  6. WWDC 2025 Highlights: Apple Unveils iOS 26, macOS 26 and Liquid Glass UI
  7. Samsung Galaxy Z Fold 7 Claimed to Be Thinnest, Lightest Foldable to Date
  8. Tata Motors to Invest up to $4 Billion Over Five Years for EVs, New Cars
  9. Lava Storm Play 5G, Storm Lite 5G Design Teased; India Launch Date Set
  10. Nothing Phone 3 Leaked Render Suggests Design, Triple Rear Camera Unit
  1. Realme GT 7, Realme GT 7T Get Up to Rs. 6,000 Discount for a Limited Time in India
  2. Nothing Phone 3 Leaked Render Suggests Transparent Back Panel, Triple Rear Cameras, No Glyph Interface
  3. ChatGPT Down: Thousands of Users Report Problems While Generating Responses, Video Generation on Sora
  4. Hollow Knight: Silksong Will Release Before Holiday 2025, Not Tied to Xbox Ally Launch, Developer Says
  5. Samsung Galaxy S25 Ultra Allegedly Saves Life by Stopping Shrapnel; Samsung Offers Free Repair
  6. WWDC 2025: Xcode 26 Adds ChatGPT Integration, Support for Other AI Models
  7. Vivo Y400 Pro Design, Key Specifications Leaked; Tipped to Get Dimensity 7300 SoC, 5,500mAh Battery
  8. Motorola Edge 60 With MediaTek Dimensity 7400 SoC, Triple Rear Cameras Launched in India: Price, Features
  9. iPadOS 26 Brings Improved Multitasking With New Windowing System, Menu Bar, and More
  10. WWDC 2025: visionOS 26 Announced With Improvements to Personas and New Spatial Features
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.