Don’t do SECURITY. Do business SECURELY.

WhatsApp flaw lets attackers install spyware with a missed call

WhatsApp urges its 1.5 billion users to update after a flaw in its calling feature was used to install spyware linked to NSO Group.

WhatsApp confirmed that attackers had exploited a flaw in its voice-calling feature to install surveillance software on phones, even if the call was not answered. The spyware was linked to the Israeli company NSO Group, and WhatsApp urged all users to update the app.

What happened

  • The vulnerability, first reported by the Financial Times, affected both Android and iPhone versions of the app.
  • WhatsApp said a select number of users had been targeted and asked its roughly 1.5 billion monthly users to update as a precaution.
  • Researchers at Citizen Lab said a human rights lawyer had been targeted.
  • In October 2019 WhatsApp sued NSO Group in the US, alleging around 1,400 users had been targeted; NSO denied wrongdoing.

Why it mattered

The case showed that commercial spyware could compromise a fully patched phone without any user interaction, and it began a long legal battle between WhatsApp and NSO Group. It also prompted wider calls for tighter controls on the sale of surveillance tools to governments.

Lessons for organisations

Keep mobile devices and apps updated promptly, manage corporate phones through mobile device management, and give extra protection to staff at higher risk of targeting.

Sources: Euronews, Amnesty International

Part of our Top stories archive of headline-making events in information security, privacy, and AI. If you would like help applying the lessons to your organisation, contact us.

Get our weekly insights by emailA free weekly threat and vulnerability round-up with our threat log spreadsheet, plus legal, regulatory, standards, and AI updates.
Subscribe free

More insights