Calendar An icon of a desk calendar. Cancel An icon of a circle with a diagonal line across. Caret An icon of a block arrow pointing to the right. Email An icon of a paper envelope. Facebook An icon of the Facebook "f" mark. Google An icon of the Google "G" mark. Linked In An icon of the Linked In "in" mark. Logout An icon representing logout. Profile An icon that resembles human head and shoulders. Telephone An icon of a traditional telephone receiver. Tick An icon of a tick mark. Is Public An icon of a human eye and eyelashes. Is Not Public An icon of a human eye and eyelashes with a diagonal line through it. Pause Icon A two-lined pause icon for stopping interactions. Quote Mark A opening quote mark. Quote Mark A closing quote mark. Arrow An icon of an arrow. Folder An icon of a paper folder. Breaking An icon of an exclamation mark on a circular background. Camera An icon of a digital camera. Caret An icon of a caret arrow. Clock An icon of a clock face. Close An icon of the an X shape. Close Icon An icon used to represent where to interact to collapse or dismiss a component Comment An icon of a speech bubble. Comments An icon of a speech bubble, denoting user comments. Comments An icon of a speech bubble, denoting user comments. Ellipsis An icon of 3 horizontal dots. Envelope An icon of a paper envelope. Facebook An icon of a facebook f logo. Camera An icon of a digital camera. Home An icon of a house. Instagram An icon of the Instagram logo. LinkedIn An icon of the LinkedIn logo. Magnifying Glass An icon of a magnifying glass. Search Icon A magnifying glass icon that is used to represent the function of searching. Menu An icon of 3 horizontal lines. Hamburger Menu Icon An icon used to represent a collapsed menu. Next An icon of an arrow pointing to the right. Notice An explanation mark centred inside a circle. Previous An icon of an arrow pointing to the left. Rating An icon of a star. Tag An icon of a tag. Twitter An icon of the Twitter logo. Video Camera An icon of a video camera shape. Speech Bubble Icon A icon displaying a speech bubble WhatsApp An icon of the WhatsApp logo. Information An icon of an information logo. Plus A mathematical 'plus' symbol. Duration An icon indicating Time. Success Tick An icon of a green tick. Success Tick Timeout An icon of a greyed out success tick. Loading Spinner An icon of a loading spinner. Facebook Messenger An icon of the facebook messenger app logo. Facebook An icon of a facebook f logo. Facebook Messenger An icon of the Twitter app logo. LinkedIn An icon of the LinkedIn logo. WhatsApp Messenger An icon of the Whatsapp messenger app logo. Email An icon of an mail envelope. Copy link A decentered black square over a white square.

WhatsApp users urged to update app following spyware vulnerability

The Facebook-owned app believes a select number of users were targeted by an advanced cyber actor.
The Facebook-owned app believes a select number of users were targeted by an advanced cyber actor.

Cybersecurity experts have warned WhatsApp users to update the messaging app as soon as possible following the discovery of a major vulnerability that could allow attackers to install a malicious code on smartphones.

The Facebook-owned app said it identified and fixed the issue earlier this month but Citizen Lab, a research group at the University of Toronto, suspects that an attacker attempted to exploit it again on Sunday.

WhatsApp believes that a select number of users were targeted by an advanced cyber actor, exploiting its voice calling feature, which it said had all the hallmarks of a private company reportedly that works with governments to deliver spyware that takes over the functions of mobile phone operating systems.

WhatsApp is urging people to update their app out of abundance of caution

“It demonstrates the importance of keeping your software updated,” said Dr Budi Arief, a cybersecurity expert at the University of Kent.

“I’m not particularly surprised by this development, this happens all the time.

“This recent vulnerability bears a resemblance to the Apple FaceTime vulnerability discovered earlier this year.

“At this stage, it is too early to say whether there is any connection between the WhatsApp vulnerability and the FaceTime vulnerability.

“Software is a very complex system – it’s practically impossible to guarantee it is completely bug-free, there are always potential vulnerabilities that could be exploited.”

WhatsApp said it was deeply concerned about the abuse of such capabilities and is also urging users to update their apps out of an abundance of caution.

The company, which has some 1.5 billion users worldwide, has been in contact with a number of human rights organisations to share information on the incident, as well as US law enforcement to assist in conducting an investigation.

“WhatsApp encourages people to upgrade to the latest version of our app, as well as keep their mobile operating system up to date, to protect against potential targeted exploits designed to compromise information stored on mobile devices,” a spokeswoman said.

“We are constantly working alongside industry partners to provide the latest security enhancements to help protect our users.”

There are concerns that the software was used in attempts to access the phones of human rights campaigners, including a UK-based lawyer.

According to the Financial Times, the spyware was developed by NSO Group, an Israeli cybersecurity and intelligence company.”Under no circumstances would NSO be involved in the operating or identifying of targets of its technology, which is solely operated by intelligence and law enforcement agencies,” the company told the paper.

“NSO would not, or could not, use its technology in its own right to target any person or organisation, including this individual (the UK lawyer).”

The National Cyber Security Centre (NCSC) has reiterated the importance of keeping devices up to date and published guidance in response to the incident.

“WhatsApp have today announced a vulnerability that could have allowed users’ phones to be compromised,” an NCSC spokesman said.

“The company has reportedly said that a small number of accounts have been affected and has told its users to update their apps using standard updates from the app store as a precaution.

“The NCSC has published guidance for users and always recommends that people protect their device by installing updates as soon as they become available.

“The NCSC also recommends that people switch on automatic updates to install them as quickly as possible.”