

These encryption processes caught our attention, and we decided to try to reverse the WhatsApp’s algorithm to decrypt the data. WhatsApp does not have the ability to view these messages. To demonstrate the severity of this vulnerability in WhatsApp, we created a tool that allows us to decrypt WhatsApp communication and spoof the messages.Īs is well-known, WhatsApp encrypts every message, picture, call, video or any other type of content you send so that only the recipient can see it. From Check Point Research’s perspective, we believe these vulnerabilities to be of the utmost importance and require attention. But, we found that it is still possible to manipulate quoted messages and spread misinformation from what appear to be trusted sources.įollowing the process of Responsible Disclosure, Check Point Research informed WhatsApp of its findings. WhatsApp fixed the 3rd vulnerability which enabled threat actors to send a private message to another group participant disguised as a public message for all.

Given all the chatter, the potential for online scams, rumors and fake news is huge. And, the number of WhatsApp users in USA is predicted to grow to 25.6 million by 2021.

The average user checks WhatsApp more than 23 times per day. Research By: Dikla Barda, Roman Zaikin and Oded VanunuĪccording to sources, WhatsApp, the Facebook-owned messaging application has over 1.5 billion users in over 180 countries. Black Hat 2019 – WhatsApp Protocol Decryption for Chat Manipulation and More
