WhatsApp Vulnerability Left iPhones Vulnerable to Israeli Spyware [Updated] - MacRumors
Skip to Content

WhatsApp Vulnerability Left iPhones Vulnerable to Israeli Spyware [Updated]

by

whatsappWhatsApp today disclosed a vulnerability that allowed hackers to remotely exploit a bug in the app's audio call system to access sensitive information on an iPhone or Android device.

According to The New York Times, attackers were able to insert malicious code into WhatsApp, allowing them to steal data, regardless of whether or not a WhatsApp phone call was answered.

Security researchers said that the spyware that took advantage of this flaw featured characteristics of the Pegasus spyware from NSO Group, which is normally licensed to governments who purchase the spyware for installing on the devices of individuals who are the target of an investigation.

Description:A buffer overflow vulnerability in WhatsApp VOIP stack allowed remote code execution via specially crafted series of SRTCP packets sent to a target phone number.

Affected Versions: The issue affects WhatsApp for Android prior to v2.19.134, WhatsApp Business for Android prior to v2.19.44, WhatsApp for iOS prior to v2.19.51, WhatsApp Business for iOS prior to v2.19.51, WhatsApp for Windows Phone prior to v2.18.348, and WhatsApp for Tizen prior to v2.18.15.

The vulnerability was described by WhatsApp as "nontrivial to deploy, limiting it to advanced and highly motivated actors," but it's not clear how long the security flaw was available nor how many people were affected. It was used to target a London lawyer who has been involved in lawsuits against the NSO Group, and security researchers believe others could have been targeted as well.

WhatsApp engineers "worked around the clock" to address the vulnerability, and made a patch available on Monday. The initial vulnerability was discovered ten days ago after WhatsApp found abnormal voice calling activity following complaints from the aforementioned lawyer. WhatsApp says that it has notified the Department of Justice and a "number of human rights organizations" about the issue.

Update: Reader comments suggested that some of the wording in this article was confusing or misleading, so we have updated it to make sure the details of the vulnerability are clear. Specifically, this issue impacted WhatsApp, not the iOS operating system.

Note: Due to the political nature of the discussion regarding this topic, the discussion thread is located in our Politics, Religion, Social Issues forum. All forum members and site visitors are welcome to read and follow the thread, but posting is limited to forum members with at least 100 posts.

Top Rated Comments

Slix Avatar
94 months ago
Remember all the comments the other day about WhatsApp being more secure than iMessage?

:rolleyes:
Score: 25 Votes (Like | Disagree)
macfacts Avatar
94 months ago
Remember all the comments the other day about WhatsApp being more secure than iMessage?

:rolleyes:
So a bug in WhatsApp can install unsigned apps? That sounds like iOS has the bigger security bug
Score: 10 Votes (Like | Disagree)
realtuner Avatar
94 months ago
So a bug in WhatsApp can install unsigned apps? That sounds like iOS has the bigger security bug
Nah, not on iOS, it's so private and secure things like this or the carrier tracking situation could never be an iPhone issue. Yeah Privacy Timmy!
Two ridiculous comments. So if iOS is the problem, how come the fix was done via a patch to the WhatsApp App itself and also a server side update to WhatsApp? How come there's no updates for iOS or Android (since, you know, this exploit also worked with WhatsApp on Android) to fix this issue?

NVM, because Apple.
Score: 7 Votes (Like | Disagree)
Mascots Avatar
94 months ago
How did this vulnerability make it past the App Store review process? Do app reviewers take bribes to allow spy trash like this into apps?
This exploit is sideloaded and delivered to WhatsApp outside of the App Store.

The App Store itself does not vet apps for vulnerabilities (that would be impossible), but it does vet them for these types of warez directly.
[doublepost=1557803453][/doublepost]
So a bug in WhatsApp can install unsigned apps? That sounds like iOS has the bigger security bug
I just searched a little and it looks like this exploit is scoped solely to WhatsApp's VOIP stack (and within the sandbox) and whatever WhatsApp had permissions for. It will access all of your photos, if you've allowed WhatsApp access, for example.

I can't find any evidence of any additional system exploiting, yet. But this seems why it's able to affect such a wide range of systems - it is spyware within WhatsApp itself.
Score: 7 Votes (Like | Disagree)
Marshall73 Avatar
94 months ago
not as bad as the FaceTime bug/exploit.
I’d say it’s arguably worse as they could remote install software to your phone which could do any number of things including scraping all of your information stored on the phone.
Score: 6 Votes (Like | Disagree)
gnasher729 Avatar
94 months ago
I found a link to the original Times article, and it is clear that the MacRumors article is mixing things up.

From the article: "Digital attackers could use the vulnerability to insert malicious code and steal data from an Android phone or an iPhone simply by placing a WhatsApp call, even if the victim did not pick up the call." So WhatsApp has a vulnerability, which lets an attacker break into the WhatsApp up. No mention of installing applications on the phone. No mention that they could affect anything outside WhatsApp.

Then later the article says that in 2016 the same company producing this exploit _was_ able to install software on an iPhone, using vulnerabilities that were present in 2016. So they cannot do this today, with or without WhatsApp exploit.

Yes I was thinking that. I mean Whatspp was obviously buggy, or considering Facebook own it it was by design.... anyway, it had this bug that allowed it to completely bypass any and all iOS security??
That’s a failure of the iOS coding is it not? It’s not protecting those back doors.
According to the New Times article, which is much clearer than the MacRumors one, no. There was no exploit against iOS. This attack was against the WhatsApp app only.
Score: 3 Votes (Like | Disagree)

Popular Stories

Whatsapp Feature

WhatsApp Now Lets You Reserve a Username

Monday June 29, 2026 4:01 pm PDT by
Popular messaging app WhatsApp is now allowing users to reserve usernames ahead of plans to launch username-based messaging. Right now, WhatsApp uses a person's phone number as an identifier, but usernames will allow people to interact without having to exchange personal information. Username reservations are rolling out starting this week, and not all users will have access to the...
Whatsapp Feature

WhatsApp Beta Adds Green Dot to Show Who's Online

Monday July 6, 2026 3:56 am PDT by
WhatsApp appears to be introducing a new visual indicator that shows when a contact is online, according to WaBetaInfo. The feature adds a small green circle to a contact's profile photo when they're active in the app, and which disappears the moment they leave, all updated in real time. The indicator is now being tested for the WhatsApp iPhone app in TestFlight after it debuted on Android...
Whatsapp Feature

WhatsApp Beta Reveals iCloud Backup Alternative for iPhone

Tuesday July 14, 2026 3:06 am PDT by
WhatsApp is developing a first-party cloud storage option for chat backups on iPhone, providing users with an alternative to iCloud for the first time, according to app tinkerer WABetaInfo. Code found in the WhatsApp beta for iOS (version 26.28.10.16), available through TestFlight, suggests that users will eventually be able to pick their preferred backup destination directly from the app's...