WhatsApp Messenger Address Book Remote Information Disclosure Vulnerability
24 Apr. 2013
Summary
Whatsapp messenger address book remote information disclosure vulnerability
Credit:
The information has been provided by Dutch Data Protection Authority - Dutch Data Protection Authority The Office of the Privacy Commissioner of Canada - The Office of the Privacy Commissioner of Canada.
WhatsApp Messenger contains a flaw that may lead to unauthorized disclosure of potentially sensitive information. The issue is due to the program not deleting information of users who ultimately opted not to use the application after a scan of a user's contact list has been performed. The application transmits the information and stores it on a server in hash form. This may allow a remote attacker to gain access to phone numbers of arbitrary people by sniffing network traffic. In addition, WhatsApp maintains a copy of this data even after the application is uninstalled