独家

、漏洞在WhatsApp iOS的警告用户

印度计算机紧急响应小组(、)已经警告用户的多个漏洞WhatsApp和iOS WhatsApp业务允许远程攻击者绕过安全限制或在目标系统上执行任意代码。

、漏洞在WhatsApp iOS的警告用户
新德里:印度的计算机紧急响应小组()已经警告用户多个漏洞WhatsApp和WhatsApp业务iOS这可能允许远程攻击者绕过安全限制或在目标系统上执行任意代码。

屏幕锁定功能中的一个漏洞被发现在WhatsApp和iOS WhatsApp业务由于输入,授权不当、在一个漏洞报告中称。

攻击者可以利用此漏洞通过使用Siri虚拟助理交流即使手机处于锁定状态,报告中称上周进行一个“高”的严重性评级。

另一个漏洞被发现在日志库WhatsApp iOS和WhatsApp业务,因为所谓的“use-after-free”错误。

远程攻击者可以利用此漏洞,向目标用户发送特别制作的动画贴纸在搁起WhatsApp视频通话时,导致一些事件发生在序列,、说。

成功利用此漏洞可能导致内存损坏,拒绝服务条件或远程代码执行。

保护自己免受这些漏洞,用户应该安装和更新最新版本的WhatsApp WhatsApp业务从应用商店,、说。

遵循和联系我们,脸谱网,Linkedin,Youtube
\"CERT-In<\/figure>New Delhi: The Indian Computer Emergency Response Team<\/a> (CERT-In<\/a>) has warned users of multiple vulnerabilities in WhatsApp<\/a> and WhatsApp Business for iOS<\/a> which could allow a remote attacker to bypass security restrictions or execute arbitrary code on the target system.

One vulnerability was found in the Screen Lock feature in WhatsApp and WhatsApp Business for iOS due to improper authorisation of input, CERT-In said in a vulnerability note.

An attacker could exploit this vulnerability by using the Siri virtual assistant to communicate even after the phone is locked, said the note last week which carried a \"high\" severity rating.