Flaws in Telegram & WhatsApp on Android Put Data at Risk

TL;DR – Time to check settings on your Android devices. Make sure you save media files to internal storage…:

[…] In the blog post on the vulnerability, the researchers point out image manipulation, in which faces are changed or individuals inserted into images; audio manipulation, in which a “deepfake” technology makes it seem an individual is saying something they never actually said; invoice manipulation, in which the amount and payment details in a legitimate invoice are changed to send money into the attacker’s account; and “fake news,” in which the material sent out by a legitimate news organization is changed to become inaccurate, as possible harm from media file jacking.

To add to the vulnerability’s seriousness, “You don’t have to attack Telegram or WhatsApp for this to happen,” says Guerra. “A device that already has malware that’s monitoring for external storage could be vulnerable to replaced documents.”

[…]

As for protection against the vulnerabilities, both Guerra and Freire say that some steps will be up the individual device owners — like setting WhatsApp to store files in internal storage and not using the “Gallery” function of Telegraph.

In addition, Freire points to the importance of saving archival copies of any corporate information transmitted by either app (or other messaging apps). In an era that sees the possibility of “deepfakes,” they are necessary insurance against unwanted information going out to employees or customers.

Original article here