Monday, April 28, 2025
HomeSecurity NewsSecurity Flaws Identified in WhatsApp Could Allow Attackers to Spy on Group...

Security Flaws Identified in WhatsApp Could Allow Attackers to Spy on Group Chats

Published on

SIEM as a Service

Follow Us on Google News

End-to-end encryption is the major security feature of secure instant messengers, among the most popular one is WhatsApp having more than one billion users.

Security researchers discovered vulnerabilities with Whatsapp and Signal which allows an attacker to add themselves to the group chat. But the risk associated with the attack is limited.

Researchers say that “if anyone that control over the WhatsApp’s servers could add new users to the WhatsApp group without the administrator permission“, it also affect signal and Threema but the impact is less.

- Advertisement - Google News

Also Read Ransomware Attack Response and Mitigation Checklist

Centralized Messaging Servers

Security Instant messaging apps should satisfy general security goals and the group messages also should have the same measures.

Security researchers said the confidentiality is broken as soon as the uninvited member can obtain all the new messages and read them,” says Paul Rösler, one of the Ruhr University researchers who co-authored a paper on the group messaging vulnerabilities. Reported Wired.

Instant Security messengers use centralized authentication and all the messages transferred through a central server that receives catches and forwards messages.

Vulnerability Impact – WhatsApp flaw

Researchers say both the Whatsapp and Signal failed to Authenticate group messages, the Vulnerability allows an attacker who controls the WhatsApp server or breaks into Transport layer can get full control over a group.

With Signal everyone in the group is an administrator every one in the group can add new users “Researchers discovered the signal management doesn’t check that you are the member of the group before adding a new user”.
In WhatsApp only the administrator authorized to add users and to management messages and it is no signed by administrators, “so the malicious WhatsApp server or if the attacker has control over WhatsApp server can add new users”.

Fix Suggested by researchers

The signal could reach Traceable Delivery by treating receipt messages like content messages and thus end-to-end encrypt them.

Researchers suggested WhatsApp for providing Traceable Delivery by signing the messages with the administrator’s group signature key.

In Threema there is already a message ID appended to every message, this ID only needs to be cryptographically bound to the message.

Researchers Concluded, “We fill this gap by providing a security model and a methodology for analyzing group instant messaging protocols“.

While our investigation focuses on three major instant messaging applications, our methodology, and the underlying model is of generic purpose and can be applied to other secure groups instant messaging protocols as well.

Researchers from Ruhr University Bochum in Germany published the paper in at the At the Real World Crypto security conference.

Gurubaran
Gurubaran
Gurubaran is a co-founder of Cyber Security News and GBHackers On Security. He has 10+ years of experience as a Security Consultant, Editor, and Analyst in cybersecurity, technology, and communications.

Latest articles

RansomHub Ransomware Deploys Malware to Breach Corporate Networks

The eSentire’s Threat Response Unit (TRU) in early March 2025, a sophisticated cyberattack leveraging...

19 APT Hackers Target Asia-based Company Servers Using Exploited Vulnerabilities and Spear Phishing Email

The NSFOCUS Fuying Laboratory’s global threat hunting system identified 19 sophisticated Advanced Persistent Threat...

FBI Reports ₹1.38 Lakh Crore Loss in 2024, a 33% Surge from 2023

The FBI’s Internet Crime Complaint Center (IC3) has reported a record-breaking loss of $16.6...

Fog Ransomware Reveals Active Directory Exploitation Tools and Scripts

Cybersecurity researchers from The DFIR Report’s Threat Intel Group uncovered an open directory hosted...

Resilience at Scale

Why Application Security is Non-Negotiable

The resilience of your digital infrastructure directly impacts your ability to scale. And yet, application security remains a critical weak link for most organizations.

Application Security is no longer just a defensive play—it’s the cornerstone of cyber resilience and sustainable growth. In this webinar, Karthik Krishnamoorthy (CTO of Indusface) and Phani Deepak Akella (VP of Marketing – Indusface), will share how AI-powered application security can help organizations build resilience by

Discussion points


Protecting at internet scale using AI and behavioral-based DDoS & bot mitigation.
Autonomously discovering external assets and remediating vulnerabilities within 72 hours, enabling secure, confident scaling.
Ensuring 100% application availability through platforms architected for failure resilience.
Eliminating silos with real-time correlation between attack surface and active threats for rapid, accurate mitigation

More like this

FBI Alerts Public to Scammers Posing as IC3 Officials in Fraud Scheme

The Federal Bureau of Investigation (FBI) has issued a warning regarding an emerging scam...

New ‘Waiting Thread Hijacking’ Malware Technique Evades Modern Security Measures

Security researchers have unveiled a new malware process injection technique dubbed "Waiting Thread Hijacking"...

EU’s GDPR Article 7 Poses New Challenges for Businesses To Secure AI-Generated Image Data

As businesses worldwide embrace digital transformation, the European Union’s General Data Protection Regulation (GDPR),...