WhatsApp urges users to upgrade app after report of spyware attack

Published May 14, 2019
The Financial Times reported that a vulnerability in WhatsApp allowed attackers to inject spyware on phones by ringing up targets using the app's phone call function. — AFP
The Financial Times reported that a vulnerability in WhatsApp allowed attackers to inject spyware on phones by ringing up targets using the app's phone call function. — AFP

Facebook's WhatsApp on Tuesday urged users to upgrade to the latest version of its popular messaging app following a report that users could be vulnerable to having malicious spyware installed on phones without their knowledge.

"WhatsApp encourages people to upgrade to the latest version of our app, as well as keep their mobile operating system up to date, to protect against potential targeted exploits designed to compromise information stored on mobile devices," a spokesman said.

"We are constantly working alongside industry partners to provide the latest security enhancements to help protect our users."

The Financial Times reported that a vulnerability in WhatsApp allowed attackers to inject spyware on phones by ringing up targets using the app's phone call function. It said the spyware was developed by Israeli cyber surveillance company NSO Group.

Asked about the report, NSO said its technology is licensed to authorised government agencies "for the sole purpose of fighting crime and terror," and that it does not operate the system itself.

"We investigate any credible allegations of misuse and if necessary, we take action, including shutting down the system. Under no circumstances would NSO be involved in the operating or identifying of targets of its technology, which is solely operated by intelligence and law enforcement agencies," the company said.

"NSO would not or could not use its technology in its own right to target any person or organisation, including this individual."

Highly invasive software

The WhatsApp spyware is sophisticated and "would be available to only advanced and highly motivated actors", the company said, adding that a "select number of users were targeted".

"This attack has all the hallmarks of a private company that works with a number of governments around the world" according to initial investigations, it added, but did not name the firm.

WhatsApp has briefed human rights organisations on the matter, but did not identify them.

The Citizen Lab, a research group at the University of Toronto, said in a tweet it believed an attacker tried to target a human rights lawyer as recently as Sunday using this flaw, but was blocked by WhatsApp.

The NSO Group came to prominence in 2016 when researchers accused it of helping spy on an activist in the United Arab Emirates. Its best-known product is Pegasus, a highly invasive tool that can reportedly switch on a target's phone camera and microphone, and access data on it.

Opinion

Editorial

Geopolitical games
Updated 18 Dec, 2024

Geopolitical games

While Assad may be gone — and not many are mourning the end of his brutal rule — Syria’s future does not look promising.
Polio’s toll
18 Dec, 2024

Polio’s toll

MONDAY’s attacks on polio workers in Karak and Bannu that martyred Constable Irfanullah and wounded two ...
Development expenditure
18 Dec, 2024

Development expenditure

PAKISTAN’S infrastructure development woes are wide and deep. The country must annually spend at least 10pc of its...
Risky slope
Updated 17 Dec, 2024

Risky slope

Inflation likely to see an upward trajectory once high base effect tapers off.
Digital ID bill
Updated 17 Dec, 2024

Digital ID bill

Without privacy safeguards, a centralised digital ID system could be misused for surveillance.
Dangerous revisionism
Updated 17 Dec, 2024

Dangerous revisionism

When hatemongers call for digging up every mosque to see what lies beneath, there is a darker agenda driving matters.