If you're sending a "View Once" message, photo, or video through WhatsApp, don't be so sure that the receiver can't view it again.
Security researchers with crypto wallet ZenGo recently discovered a bug that allowed WhatsApp users to view "View Once" messages as many times as they liked.
SEE ALSO: Meta updates WhatsApp and Messenger third-party chats in EuropeIn response, WhatsApp patched the issue. But, ZenGo researchers then discovered another exploit in WhatsApp's temporary fix that once again allowed them to access these messages that had supposedly disappeared.
WhatsApp launched its View Once feature in 2021. View Once allows users to send texts, photos, and videos that disappear after the recipient initially accesses them.
Furthermore, to ensure the ephemeral nature of these messages, WhatsApp disables screenshots from being used in the app on View Once messages through iOS and Android. In addition, WhatsApp limits View Once messages to the mobile apps only.
However, in a post last week, ZenGo Security Research Manager Tal Be'ery detailed an exploit that allowed his team to access View Once messages over and over again.
Basically, as Be'ery explains, the View Once messages are only restricted from view in the mobile apps after being viewed. The media continues to exist on WhatsApp's servers. If a user can find the URL for the media file, they can access the message or media file that was supposed to have disappeared.
Be’ery went through the official channels with WhatsApp's parent company Meta and reported the exploit through their bug bounty program on August 26. It was too late though. Be'ery soon found that the bug was already in the wild, as a Chrome extension popped up allowing users to access their already-viewed View Once messages through WhatsApp's web app. ZenGo went public with the exploit and published their report last week on Sept. 9.
It appears the issue has been taken seriously by Meta, at least after Be’ery went public with the exploit. Meta appears to have released a fix for the WhasApp View Once bug on Sept. 12.
According to a new reportby Be'ery, Meta's patch "changes the way View Once media messages are saved to the application’s databases and redact some of the information that enables the media viewing."
The fix appears to have broken the previously mentioned "View Once Photos Bypass" Chrome extension as well.
Tweet may have been deleted
But, the fix is "still not enough," according to Be'ery and can be exploited with a workaround. In fact, as Be'ery discovered, the creator of the View Once bypass Chrome extension published an update saying that they've already discovered a new exploit in order to once again access View Once media.
Be'ery also publisheda video showing how View Once messages are still accessible.
Meta told Mashable that it's taking multiple steps to deal with the View Once issue. The initial fix was meant to be temporary as Meta restructures how View Once works in WhatsApp on the web.
"As we said before, we are in the process of rolling out multiple updates to View Once on web," a WhatsApp spokesperson told Mashable. "Those additional updates are forthcoming."
UPDATE: Sep. 18, 2024, 2:04 p.m. EDT This piece has been updated with a statement and additional information from Meta.
Copyright © 2023 Powered by
WhatsApp 'View Once' messages are far more permanent than you realize (at least for now)-鼓盆之戚网
sitemap
文章
6316
浏览
4
获赞
69221
Robocalls, WeChat messages, and more spread misinformation on Election Day
It's Nov. 3, Election Day, and you know what that means: Misinformation will be flooding the interneThe story behind Pluto's huge moon bodes well for distant ocean worlds
Unlike how scientists believe Earth's moon formedbillions of years ago, Plutoand its biggest moon, CIs the Ryzen 9800X3D Truly Faster for Real
The number of misconceptions in the tech world can be overwhelming, but few are more frustrating thaLive BBC interview gets derailed by bizarrely awkward man
Oh how we love an awkward TV blunder. In the aftermath of BBC Dad, a clip of another gloriously awkwSamsung Galaxy Z Flip 5G is available for preorder
Just a few days before Samsung's Galaxy Unpackedevent on Aug. 5, the company has listed its Galaxy ZElon Musk warns that AI could become an 'immortal dictator'
Authoritarianism is nothing new. But at least Mussolini and Hitler died. In the age of artificial inUnder Armour notifies app users of massive data breach
Under Armour's digital security is out of shape. The athletic apparel company today announced a masApple's RCS messaging support expands to a lot of new carriers
In late 2023, Apple finally added RCS support for the iPhone. RCS – or Rich Communication ServWhy GMC's new electric Hummer is a bigger deal than Tesla's Cybertruck
There were no broken windows, like the "bulletproof" ones at Tesla's Cybertruck event last year thatTechSpot PC Buying Guide: 2H 2024
It's been a rather uneventful year in the PC hardware market. Most of us were hoping that AMD's RyzeFacebook: Your profile data has probably been scraped
Our Facebook privacy nightmare somehow keeps getting worse.The vast majority of Facebook users haveKendall Jenner is proving just how meaningless everything she does is
As foretold by TMZ, Kendall Jenner reemerged from her shame spiral at Coachella to embrace the void.Apple's iPhone 12 studio lets you mix and match iPhone colors and accessories
Unsure which iPhone 12 color would match best with a Saddle Brown MagSafe Wallet? Apple has a fix.OvEssential Apps to Install on your Windows PC or Mac
You just bought a new laptop, built a new desktop PC, or are simply clean installing on a new solidExplainer: What is Chip Binning?
You just bought a new CPU or graphics card, and fired it up in your PC. It seems to run pretty cool,