
Cloud Vulnerability DB
A community-led vulnerabilities database
A cache configuration vulnerability (CVE-2021-24027) was discovered in WhatsApp for Android and WhatsApp Business for Android versions prior to v2.21.4.18. The vulnerability allowed third parties with access to the device's external storage to read cached TLS material (MITRE).
The vulnerability leverages Chrome's support for content providers in Android through the 'content://' URL scheme and involves a same-origin policy bypass in the browser (CVE-2020-6516). The flaw allows attackers to send specially-crafted HTML files to victims over WhatsApp, which when opened in the browser, could execute malicious code. The vulnerability exposes TLS session key details stored in an unprotected external storage area, making them accessible to any app with read/write permissions (Hacker News).
The vulnerability could allow attackers to compromise WhatsApp communications, achieve remote code execution on the victim's device, and extract Noise protocol keys used for end-to-end encryption in user communications. Additionally, attackers could access sensitive information stored in the external storage area, including TLS session materials (Hacker News).
The exploit requires an attacker to lure the victim into opening an HTML document attachment. When opened in Chrome through WhatsApp, the attacker's JavaScript code could steal stored TLS session keys. This vulnerability affects devices running Android versions up to and including Android 9 (Hacker News).
Users are recommended to update to WhatsApp version 2.21.4.18 or later to mitigate the risk. Google has also introduced 'scoped storage' in Android 10 as a defensive measure, which provides isolated storage areas for each app, preventing unauthorized access from other applications (Hacker News).
WhatsApp has confirmed that the end-to-end encryption continues to work as intended and users' messages remain secure. The company acknowledged the researchers' findings and implemented improvements to protect users when visiting malicious websites on Chrome (Hacker News).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."