So this morning I open Twitter with my coffee like always, and the first thing in my feed is a Financial Times headline about WhatsApp letting attackers install spyware on your phone just by calling you. Not even answering the call. Just the call happening was apparently enough to slip code onto the device, and then the call would sometimes vanish from your log like nothing happened.
I read it twice because it seemed too dumb to be true, and then I remembered that "too dumb to be true" describes about half the security world these days.
Here's the actual mechanics as best I can tell: there's a buffer overflow bug in WhatsApp's VOIP stack (the part that handles calls, obviously), and if you send someone a specially crafted call, you can get malicious code running on their phone before they've done anything at all. No tapped link, no sketchy attachment, no "click here to claim your prize." Just a phone ringing. WhatsApp pushed a server-side fix over the weekend and is telling everyone to update the app right now regardless, since the server fix alone apparently doesn't cover everything.
The spyware in question reportedly traces back to NSO Group, the Israeli firm that makes surveillance tools it insists are only sold to governments for legitimate law enforcement and counterterrorism use. Sure. One case being reported is a UK human rights lawyer who got hit with this. Make of that what you will.
I went and checked my own phone the second I finished the article, which, embarrassingly, is not my usual behavior. I am one of those people who lets app updates pile up for two weeks because the "update all" button feels like a chore and I'm always in the middle of something else. My App Store badge routinely sits at like 14 unopened updates. This is the first time in recent memory I've gone and manually pulled a single update the moment I heard about it, badge count be damned.
And that's kind of the thing that's bugging me today, pun sort of intended. We've all been trained to treat app updates as background noise. Little red numbers, mild guilt, ignore and move on. But this is exactly the kind of bug that makes the case for why that habit is bad: the fix exists, it went out over the weekend, and if you're one of the (we're told) small number of targeted users who hasn't updated yet, you're just sitting there exposed for no reason other than inertia. WhatsApp is downplaying the scope, saying it was a "select number" of users, which is corporate-speak for "we genuinely don't know the full extent yet and would like you to feel calm."
I don't think I'm on anyone's target list. I'm not a journalist covering anything sensitive, I'm not a lawyer, I'm not an activist. My WhatsApp usage is mostly my mother trying to video call me at hours that make no sense for either of our time zones, and a group chat with three guys I went to university with who mostly send each other Premier League memes. But that's not really the point. The point is that an app installed on something like 1.5 billion phones had a hole you could drive a truck through, and the mechanism for getting in required zero user interaction. That's the scary category of bug. The ones where being careful doesn't save you.
Facebook owns WhatsApp, for anyone who forgot, which means this lands on a company that was already having kind of a rough year on the "can we be trusted with your data" front. I'm not going to pretend this is some huge new scandal on that scale, it's a different kind of failure, a technical one rather than a policy one. But if you're already primed to be annoyed at Facebook for other reasons, this isn't going to help.
Anyway. Go update WhatsApp. It'll take you forty five seconds. I know the badge count is annoying but this is the one time this month it's actually worth clearing.