City
Epaper

Facebook fixes Instagram bug that turns phones into spying tools

By IANS | Updated: September 26, 2020 15:18 IST

New Delhi, Sep 26 Facebook has patched a critical vulnerability in Instagram that could have given an attacker the ...

Open in App

New Delhi, Sep 26 Facebook has patched a critical vulnerability in Instagram that could have given an attacker the ability to take over a victims Instagram account, and turn their phone into a spying tool, simply by sending them a malicious image file.

When the image is saved and opened in the Instagram app, the exploit would give the hacker full access to the victim's Instagram messages and images, allowing them to post or delete images at will, as well as giving access to the phone's contacts, camera and location data, according to cyber security researchers at Check Point.

An attack can be triggered once a malicious image is sent via email or WhatsApp and then saved on a victim's device.

The researchers revealed the critical vulnerability as remote code execution (RCE) that allows an attacker to take over a computer or a server by running arbitrary malicious software (malware).

"This vulnerability can allow an attacker to perform any action they wish in the Instagram app. Since the Instagram app has very extensive permissions, this may allow an attacker to instantly turn the targeted phone into a perfect spying tool – putting the privacy of millions of users at serious risk," the cyber security firm revealed in a blog post on Friday.

Instagram is one of the most popular social media platforms globally, with over 100 million photos uploaded every day, and nearly 1 billion monthly active users.

"The vulnerability we found was in the way that Instagram used Mozjpeg– an open source project used by Instagram as its JPEG format image decoder for images uploaded to the service," the researchers explained.

The company disclosed the findings to Facebook and the Instagram team.

Facebook described the vulnerability as an "Integer Overflow leading to Heap Buffer Overflow" and issued a patch to remediate the issue on the newer versions of the Instagram application on all platforms.

"The patch for this vulnerability has already been available for 6 months prior to this publication, giving time to the majority of users to update their Instagram applications, thus mitigating the risk of this vulnerability being exploited," the researchers informed.

"We strongly encourage all Instagram users to ensure they are using the latest Instagram app version and to update if any new version is available".

 

( With inputs from IANS )

Disclaimer: This post has been auto-published from an agency feed without any modifications to the text and has not been reviewed by an editor

Tags: InstagramFacebookTwitter and instagramInstagram and twitterFacebook-owned instagramInstagram for androidInstaFacebook connectivityAfter facebook
Open in App

Related Stories

MaharashtraShiv Sena Jalna MLA Arjun Khotkar, Son Receive Death Threats on Instagram; Police Launch Probe

NationalHaryana Shocker: YouTuber Strangles Husband With Dupatta, Dumps Body With Lover's Help; CCTV Footage Emerges

InternationalMark Zuckerberg May Lose Instagram and WhatsApp Amid Antitrust Case Against Meta

TechnologyInstagram to Launch Locked Reels Feature Soon, Could Help Boost Followers

Social ViralA US Woman Flies to an Andhra Pradesh Village To Meet Her Instagram Boyfriend (Watch Video)

Technology Realted Stories

TechnologyTransport Ministry hauls up Ola Electric over missing trade certificates, EV firm responds

TechnologyKia reports record Q1 sales on hybrids, high-value vehicle demand

TechnologyApple may shift entire iPhone assembly for US to India by next year: Report

TechnologyChildren with chronic conditions at risk for severe RSV outcomes: Study

TechnologyCNG fuel stations surge by 2,300 pc, PNG use up 467 pc in 10 years: Hardeep Puri