Sunday, 19 January 2025
25 C
Singapore

WhatsApp for Windows security flaw leaves user safety in their own hands

Discover how a security flaw in WhatsApp for Windows impacts users and what you can do to stay safe.

The Windows client for the widely used instant messaging platform WhatsApp had a notable security flaw. However, Meta, the owner of WhatsApp, doesnโ€™t see it as their responsibility to fix it. Instead, they believe it’s up to you to be cautious and avoid getting infected. The good news is that the risk of this flaw affecting you is quite low, so you should be safe.

A security flaw was discovered

Security researcher Saumyajeet Das examined WhatsApp for Windows to identify which file types the client can run natively. Most risky file types, such as .EXE, .COM, .SCR., or .BAT were blocked and can only be run if first saved to the computerโ€™s hard drive. However, there are a few that the client runs directly – .PYZ (Python ZIP app), .PYZW (PyInstaller programme), and .EVTX (Windows event Log file).

This means that if you click โ€œOpenโ€ on any of these files in WhatsApp, they will execute immediately, including any malicious code. But there’s a catchโ€”for this to happen, you need to install Python on your computer, which few people do.

Limited impact

According to BleepingComputer, the requirement to have Python installed limits the targets for software developers, researchers, and power users. Das reported the issue to Meta in early June 2024 and received a response a month and a half later. Meta acknowledged the problem but indicated it had been reported before and stated they wouldnโ€™t address it.

In a statement to BleepingComputer, Meta explained that itโ€™s the userโ€™s responsibility to avoid opening malicious files. “We’ve read what the researcher has proposed and appreciate their submission. Malware can take many forms, including through downloadable files meant to trick a user,โ€ the statement reads. “It’s why we warn users to never click on or open a file from somebody they don’t know, regardless of how they received itโ€”whether over WhatsApp or any other app.”

User responsibility

Meta’s stance is clear: users must stay vigilant and avoid opening files from unknown sources. This advice is essential for maintaining digital safety on WhatsApp and across all platforms and applications. Always be cautious with the files you download and open, and ensure you have the necessary security measures to protect your system.

The flaw in WhatsApp for Windows serves as a reminder of the importance of digital hygiene and being aware of the files you interact with online. While Meta might not fix this issue, staying informed and cautious can help you avoid potential threats and secure your computer.

Hot this week

Samsung to unveil the Galaxy S25 on January 22: What to expect

Samsung's Unpacked event on January 22 will reveal the Galaxy S25 series. Discover new features, AI advancements, and possible surprise launches.

Sterra launches dehumidifiers to improve home comfort and air quality

Sterra introduces the Ray and Titan dehumidifiers, offering advanced humidity control and air purification for healthier, more comfortable homes.

Final Fantasy VII: Rebirth for PC shows why it’s the ultimate version

Discover why Final Fantasy VII: Rebirth for PC is the ultimate version with enhanced visuals and stunning locations. Launches January 23, 2025!

Honda and Nissan explore merger to tackle challenges and grow together

Honda and Nissan are exploring a US$50 billion merger to combat Chinese competition, leverage factory capacity, and expand into larger SUVs.

How to download your TikTok videos and data before the ban

The Supreme Court has upheld a TikTok ban, and hereโ€™s how you can back up your videos and data before it happens.

Character AI tests games on its platform to boost user engagement

Character AI introduces games to its platform to boost user engagement and enhance its entertainment offerings.

How to download your TikTok videos and data before the ban

The Supreme Court has upheld a TikTok ban, and hereโ€™s how you can back up your videos and data before it happens.

ChatGPTโ€™s head of product to testify in US antitrust case against Google

ChatGPTโ€™s head of product, Nick Turley, will testify in the US governmentโ€™s antitrust case against Google, addressing AI and competition issues.

Amazon pauses drone deliveries in the US after testing crash

Amazon halts US drone deliveries after crashes during testing, citing safety concerns and working on software updates for its fleet.

Related Articles