{"id":144685,"date":"2019-07-15T17:02:27","date_gmt":"2019-07-15T15:02:27","guid":{"rendered":"http:\/\/sftarticles.wpenginepowered.com\/en\/?p=144685"},"modified":"2025-07-01T21:41:30","modified_gmt":"2025-07-02T04:41:30","slug":"whatsapp-telegram-security-flaw","status":"publish","type":"post","link":"https:\/\/cms-articles.softonic.io\/en\/whatsapp-telegram-security-flaw\/","title":{"rendered":"WhatsApp, Telegram security flaw: how to fix it"},"content":{"rendered":"<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-144686\" src=\"https:\/\/articles-img.sftcdn.net\/sft\/articles\/auto-mapping-folder\/sites\/3\/2021\/06\/700_WhatsApp_ugdvq6.jpg\" alt=\"WhatsApp secuirty\" width=\"700\" height=\"394\" \/><\/p>\n<p>We already know that you can&#8217;t believe everything you read online, but now we might not be able to trust everything we see on WhatsApp or Telegram!<\/p>\n<p>Researchers from the software company Symantec discovered a vulnerability in WhatsApp and Telegram. <strong>The vulnerability would allow a hacker to change what a person sent you.<\/strong><\/p>\n<p>In the above video, the researchers showed that through the vulnerability, they were able to <strong>change the faces in a photo to look like Nicolas Cage.\u00a0<\/strong>As hilarious, and amazing as that is, there is more to fear than a real-life version of his movie &#8220;Face\/Off.&#8221;<\/p>\n<p>Let&#8217;s say someone sent you a receipt or an invoice. A hacker could alter the information about the account, routing number, or the amount! Suddenly, rather than reimbursing someone for last night&#8217;s dinner, <strong>you just got duped into sending a stranger $50.\u00a0<\/strong><\/p>\n<h2>How could this happen?<\/h2>\n<p>WhatsApp and Telegram both use end-to-end encryption which basically means that messages are kept between those involved. <strong>Even the companies themselves cannot read the messages.\u00a0<\/strong><\/p>\n<p>However, this does not mean the app itself is safe from being hacked. This vulnerability could have allowed for a spyware attack that would have compromised WhatsApp and Telegram users.<\/p>\n<div class=\"sc-card-program\">\r\n  <div class=\"sc-card-program__body\">\r\n    <div class=\"sc-card-program__row clearfix\">\r\n      <div class=\"sc-card-program__col-logo\">\r\n        <img decoding=\"async\" class=\"sc-card-program__img\" alt=\"WhatsApp Messenger\" src=\"https:\/\/images.sftcdn.net\/images\/t_optimized,f_auto\/p\/6b5a0468-96d1-11e6-bfc6-00163ec9f5fa\/1398466786\/whatsapp-messenger-logo.png\" width=\"100px\" height=\"100px\">\r\n      <\/div>\r\n      <div class=\"sc-card-program__col-title\">\r\n        <span class=\"sc-card-program__title\">WhatsApp Messenger<\/span>\r\n        <a class=\"sc-card-program__button sc-card-program-internal\" href=\"https:\/\/whatsapp.en.softonic.com\/android\" target=\"_self\" rel=\"noopener noreferrer\">Download free \u25ba<\/a>\r\n      <\/div>\r\n      <div class=\"sc-card-program__col-rating\">\r\n        <svg class=\"rating-score__content\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" version=\"1.1\" x=\"0\" y=\"0\" viewbox=\"0 0 50 50\" enable-background=\"new 0 0 50 50\" xml:space=\"preserve\"><path class=\"rating-score__background rating-score--good\" fill=\"none\" stroke-width=\"6\" stroke-miterlimit=\"10\" d=\"M40 40c8.3-8.3 8.3-21.7 0-30s-21.7-8.3-30 0 -8.3 21.7 0 30\"><\/path><path class=\"rating-score__value rating-score__value--80\" fill=\"none\" stroke-width=\"6\" stroke-dashoffset=\"80\" stroke-miterlimit=\"10\" d=\"M40 40c8.3-8.3 8.3-21.7 0-30s-21.7-8.3-30 0 -8.3 21.7 0 30\"><\/path><text class=\"rating-score__number\" content=\"8\" text-anchor=\"middle\" transform=\"matrix(1 0 0 1 25 31.0837)\" data-auto=\"app-user-score\">8<\/text><\/svg>\r\n      <\/div>\r\n    <\/div>\r\n    <div class=\"sc-card-program__row\">\r\n      <span class=\"sc-card-program__description\"><\/span>\r\n    <\/div>\r\n    <div class=\"sc-card-program__row\">\r\n      <img decoding=\"async\" class=\"sc-card-program__bigpic\" src=\"\" onerror=\"this.style.display='none'\">\r\n    <\/div>\r\n    <a class=\"sc-card-program__link track-link sc-card-program-internal\" href=\"https:\/\/whatsapp.en.softonic.com\/android\" target=\"_self\" rel=\"noopener noreferrer\"><\/a>\r\n  <\/div>\r\n<\/div>\n<div class=\"sc-card-program\">\r\n  <div class=\"sc-card-program__body\">\r\n    <div class=\"sc-card-program__row clearfix\">\r\n      <div class=\"sc-card-program__col-logo\">\r\n        <img decoding=\"async\" class=\"sc-card-program__img\" alt=\"Telegram\" src=\"https:\/\/images.sftcdn.net\/images\/t_optimized,f_auto\/p\/dd056881-d039-479e-86c9-f30aebb46c55\/538821325\/telegram-logo.png\" width=\"100px\" height=\"100px\">\r\n      <\/div>\r\n      <div class=\"sc-card-program__col-title\">\r\n        <span class=\"sc-card-program__title\">Telegram<\/span>\r\n        <a class=\"sc-card-program__button sc-card-program-internal\" href=\"https:\/\/telegram.en.softonic.com\/\" target=\"_self\" rel=\"noopener noreferrer\">Download free \u25ba<\/a>\r\n      <\/div>\r\n      <div class=\"sc-card-program__col-rating\">\r\n        <svg class=\"rating-score__content\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" version=\"1.1\" x=\"0\" y=\"0\" viewbox=\"0 0 50 50\" enable-background=\"new 0 0 50 50\" xml:space=\"preserve\"><path class=\"rating-score__background rating-score--good\" fill=\"none\" stroke-width=\"6\" stroke-miterlimit=\"10\" d=\"M40 40c8.3-8.3 8.3-21.7 0-30s-21.7-8.3-30 0 -8.3 21.7 0 30\"><\/path><path class=\"rating-score__value rating-score__value--80\" fill=\"none\" stroke-width=\"6\" stroke-dashoffset=\"80\" stroke-miterlimit=\"10\" d=\"M40 40c8.3-8.3 8.3-21.7 0-30s-21.7-8.3-30 0 -8.3 21.7 0 30\"><\/path><text class=\"rating-score__number\" content=\"8\" text-anchor=\"middle\" transform=\"matrix(1 0 0 1 25 31.0837)\" data-auto=\"app-user-score\">8<\/text><\/svg>\r\n      <\/div>\r\n    <\/div>\r\n    <div class=\"sc-card-program__row\">\r\n      <span class=\"sc-card-program__description\"><\/span>\r\n    <\/div>\r\n    <div class=\"sc-card-program__row\">\r\n      <img decoding=\"async\" class=\"sc-card-program__bigpic\" src=\"\" onerror=\"this.style.display='none'\">\r\n    <\/div>\r\n    <a class=\"sc-card-program__link track-link sc-card-program-internal\" href=\"https:\/\/telegram.en.softonic.com\/\" target=\"_self\" rel=\"noopener noreferrer\"><\/a>\r\n  <\/div>\r\n<\/div>\n<h2>What&#8217;s being done about this?<\/h2>\n<p>There is one big thing you can do to protect yourself when using WhatsApp and Telegram: become invisible.<\/p>\n<p>The vulnerability<a href=\"https:\/\/www.symantec.com\/blogs\/expert-perspectives\/symantec-mobile-threat-defense-attackers-can-manipulate-your-whatsapp-and-telegram-media\" target=\"_blank\" rel=\"noopener noreferrer\"> comes from how files are stored on the apps<\/a>, according to Symantec. In order to close that gap, you need to <strong>remove your gallery&#8217;s visibility.\u00a0<\/strong><\/p>\n<p>In WhatsApp, turn off <strong>&#8220;Media Visibility&#8221;<\/strong> in the settings menu.<\/p>\n<p>In Telegram, toggle off <strong>&#8220;Save to Gallery&#8221;<\/strong> from the settings as well.<\/p>\n<h2>Wrapping up<\/h2>\n<p>There are many political activists, politicians, and people-of-interest who need to keep their conversations private, so they use apps like WhatsApp and Telegram. Unfortunately, instances like this and like a few months ago when <a href=\"https:\/\/en.softonic.com\/articles\/spyware-phone-tips\" target=\"_blank\" rel=\"noopener noreferrer\">a human rights lawyer was targeted in a WhatsApp virus attack<\/a>, are showing that they might not be the most secure.<\/p>\n<p>Although this security flaw was caught early, the point remains that<strong> this could have been devastating to users.\u00a0<\/strong>Next time you go to send something important on WhatsApp or Telegram, you might want to rethink it.<\/p>\n<div class=\"sc-related-articles-white\">\r\n<p class=\"sc-related-articles-white__title\">Fake WhatsApp scams <\/p>\r\n  <div class=\"sc-related-articles-white__row\">\r\n    <a title=\"Watch out for this Fake version of WhatsApp \u25ba\" href=\"https:\/\/en.softonic.com\/articles\/fake-version-of-whatsapp\/\">\r\n    <div class=\"sc-related-articles-white__article\">\r\n      <div class=\"sc-related-articles-white__image\">\r\n        <div style=\"background-image:url(https:\/\/articles-img.sftcdn.net\/sft\/articles\/auto-mapping-folder\/sites\/3\/2018\/04\/fake-whatsapp-plus.jpg)\"><\/div>\r\n      <\/div>\r\n      <div class=\"sc-related-articles-white__text\">\r\n        <p>Watch out for this Fake version of WhatsApp \u25ba<\/p>\r\n      <\/div>\r\n    <\/div>\r\n    <\/a>\r\n    <a title=\"Fake WhatsApp downloaded by more than 1 million users \u25ba\" href=\"https:\/\/en.softonic.com\/articles\/fake-whatsapp-downloaded-by-more-than-1000000-users\/\">\r\n    <div class=\"sc-related-articles-white__article\">\r\n      <div class=\"sc-related-articles-white__image\">\r\n        <div style=\"background-image:url(https:\/\/articles-img.sftcdn.net\/sft\/articles\/auto-mapping-folder\/sites\/3\/2017\/11\/whatsapp-hacker-1024x576.jpg)\"><\/div>\r\n      <\/div>\r\n      <div class=\"sc-related-articles-white__text\">\r\n        <p>Fake WhatsApp downloaded by more than 1 million users \u25ba<\/p>\r\n      <\/div>\r\n    <\/div>\r\n    <\/a>\r\n  <\/div>\r\n  <div class=\"sc-related-articles-white__row\">\r\n    <a title=\"Beware this Fake WhatsApp Update Scam \u25ba\" href=\"https:\/\/en.softonic.com\/articles\/beware-this-fake-whatsapp-update-scam\/\">\r\n    <div class=\"sc-related-articles-white__article\">\r\n      <div class=\"sc-related-articles-white__image\">\r\n        <div style=\"background-image:url(https:\/\/articles-img.sftcdn.net\/sft\/articles\/auto-mapping-folder\/sites\/3\/2017\/05\/fake-whatsapp-11.jpg)\"><\/div>\r\n      <\/div>\r\n      <div class=\"sc-related-articles-white__text\">\r\n        <p>Beware this Fake WhatsApp Update Scam \u25ba<\/p>\r\n      <\/div>\r\n    <\/div>\r\n    <\/a>\r\n    <a title=\"8 tricks to strengthen your WhatsApp security \u25ba\" href=\"https:\/\/en.softonic.com\/articles\/8-tricks-to-strengthen-your-whatsapp-security\/\">\r\n    <div class=\"sc-related-articles-white__article\">\r\n      <div class=\"sc-related-articles-white__image\">\r\n        <div style=\"background-image:url(https:\/\/articles-img.sftcdn.net\/sft\/articles\/auto-mapping-folder\/sites\/3\/2017\/11\/whatsapp-web-screenshot-1024x576.png)\"><\/div>\r\n      <\/div>\r\n      <div class=\"sc-related-articles-white__text\">\r\n        <p>8 tricks to strengthen your WhatsApp security \u25ba<\/p>\r\n      <\/div>\r\n    <\/div>\r\n    <\/a>\r\n  <\/div>\r\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>Security flaw allowed hackers to alter photos sent on WhatsApp and Telegram. <\/p>\n","protected":false},"author":9180,"featured_media":144687,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":"","wpcf-pageviews":1},"categories":[2518,2441],"tags":[2406,1624,1027,1369,1043],"usertag":[790],"vertical":[],"content-category":[],"class_list":["post-144685","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-guides","category-how-to","tag-app-subdomain-redirectiontelegram","tag-privacy","tag-security","tag-telegram","tag-whatsapp","usertag-whatsapp"],"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/posts\/144685","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/users\/9180"}],"replies":[{"embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/comments?post=144685"}],"version-history":[{"count":1,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/posts\/144685\/revisions"}],"predecessor-version":[{"id":325718,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/posts\/144685\/revisions\/325718"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/media\/144687"}],"wp:attachment":[{"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/media?parent=144685"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/categories?post=144685"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/tags?post=144685"},{"taxonomy":"usertag","embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/usertag?post=144685"},{"taxonomy":"vertical","embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/vertical?post=144685"},{"taxonomy":"content-category","embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/content-category?post=144685"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}