If you're sending a "View Once" message, photo, or video through WhatsApp, don't be so sure that the receiver can't view it again.
Security researchers with crypto wallet ZenGo recently discovered a bug that allowed WhatsApp users to view "View Once" messages as many times as they liked.
SEE ALSO: Meta updates WhatsApp and Messenger third-party chats in EuropeIn response, WhatsApp patched the issue. But, ZenGo researchers then discovered another exploit in WhatsApp's temporary fix that once again allowed them to access these messages that had supposedly disappeared.
WhatsApp launched its View Once feature in 2021. View Once allows users to send texts, photos, and videos that disappear after the recipient initially accesses them.
Furthermore, to ensure the ephemeral nature of these messages, WhatsApp disables screenshots from being used in the app on View Once messages through iOS and Android. In addition, WhatsApp limits View Once messages to the mobile apps only.
However, in a post last week, ZenGo Security Research Manager Tal Be'ery detailed an exploit that allowed his team to access View Once messages over and over again.
Basically, as Be'ery explains, the View Once messages are only restricted from view in the mobile apps after being viewed. The media continues to exist on WhatsApp's servers. If a user can find the URL for the media file, they can access the message or media file that was supposed to have disappeared.
Be’ery went through the official channels with WhatsApp's parent company Meta and reported the exploit through their bug bounty program on August 26. It was too late though. Be'ery soon found that the bug was already in the wild, as a Chrome extension popped up allowing users to access their already-viewed View Once messages through WhatsApp's web app. ZenGo went public with the exploit and published their report last week on Sept. 9.
It appears the issue has been taken seriously by Meta, at least after Be’ery went public with the exploit. Meta appears to have released a fix for the WhasApp View Once bug on Sept. 12.
According to a new reportby Be'ery, Meta's patch "changes the way View Once media messages are saved to the application’s databases and redact some of the information that enables the media viewing."
The fix appears to have broken the previously mentioned "View Once Photos Bypass" Chrome extension as well.
This Tweet is currently unavailable. It might be loading or has been removed.
But, the fix is "still not enough," according to Be'ery and can be exploited with a workaround. In fact, as Be'ery discovered, the creator of the View Once bypass Chrome extension published an update saying that they've already discovered a new exploit in order to once again access View Once media.
Be'ery also publisheda video showing how View Once messages are still accessible.
Meta told Mashable that it's taking multiple steps to deal with the View Once issue. The initial fix was meant to be temporary as Meta restructures how View Once works in WhatsApp on the web.
"As we said before, we are in the process of rolling out multiple updates to View Once on web," a WhatsApp spokesperson told Mashable. "Those additional updates are forthcoming."
UPDATE: Sep. 18, 2024, 2:04 p.m. EDT This piece has been updated with a statement and additional information from Meta.
Copyright © 2023 Powered by
WhatsApp 'View Once' messages are far more permanent than you realize (at least for now)-风花雪夜网
sitemap
文章
76
浏览
228
获赞
81
Apple and Google block UK COVID app update for breaking data
Google and Apple have blocked an update to the UK government's COVID-19 contact tracing app for breaGet 20% off Tile trackers at Amazon's Big Spring Sale 2024
Life requires us to remember a lot of things. If you struggle to remember where you left your walletGoogle quietly testing its AI search results among general users
More Google users might be getting an unprompted taste of Google's AI-assisted Search capabilities,Presidential debate livestream: Watch Harris
TL;DR: The first Harris-Trump presidential debate will be available on ABC channels, ABC News Live,You probably shouldn't give skincare as a gift
Like a lot of other people who pride themselves on organization to a point, I have a designated &ldqHow to screen record on an iPhone
Sometimes a simple screenshot doesn't suffice. When you want to show off a new app feature you're exBest Vitamix Deal: $50 off the Vitamix Explorian Blender
SAVE $50: As of today, the Vitamix Explorian Blender is on sale at Amazon for $329.95. That's 13% ofBest free AI and ChatGPT courses
TL;DR:A wide range of AI and ChatGPT courses are available to take for free on Udemy. We know you'reTwitter may be developing a new layout that makes it look more like Facebook
Twitter may soon make photos just a tiny bit wider on mobile.Noted tech detective Jane Manchun WongHow to turn off your PS5
So, you want to turn off a PlayStation 5, and you don't know how. Everyone's been there. There's noHow to turn read receipts on or off on Instagram
The rumors are true: You can change your read receipts on Instagram.The feature rolled out recentlyM3 MacBook Air vs. M2 MacBook Air: What’s the difference?
Rejoice! The M3 Macbook Air is finally available but is it really worth all the applause?Apple revea21 iPhone shortcuts that'll make your life easier (or more fun)
We're big fans of Apple's Shortcuts app. It's a time-saving widget-maker that's really fun to experiAmazon Big Spring Sale laptop deal: Get an Acer Aspire 3 for just $257
UPDATE: Mar. 22, 2024, 11:40 a.m. EDT The Acer Aspire 3 (AMD Ryzen 3 7320U, 8GB RAM, 128GB SSD)is noFlirting IRL is having a pop culture moment, from 'Chicken Shop Date' to Charli xcx
There's a unique feeling that comes with watching two people flirting wildly with each other. You're