Sunday, 15 June 2025
30.5 C
Singapore
30.5 C
Thailand
21.5 C
Indonesia
29.1 C
Philippines

WhatsApp for Windows security flaw leaves user safety in their own hands

Discover how a security flaw in WhatsApp for Windows impacts users and what you can do to stay safe.

The Windows client for the widely used instant messaging platform WhatsApp had a notable security flaw. However, Meta, the owner of WhatsApp, doesn’t see it as their responsibility to fix it. Instead, they believe it’s up to you to be cautious and avoid getting infected. The good news is that the risk of this flaw affecting you is quite low, so you should be safe.

A security flaw was discovered

Security researcher Saumyajeet Das examined WhatsApp for Windows to identify which file types the client can run natively. Most risky file types, such as .EXE, .COM, .SCR., or .BAT were blocked and can only be run if first saved to the computer’s hard drive. However, there are a few that the client runs directly – .PYZ (Python ZIP app), .PYZW (PyInstaller programme), and .EVTX (Windows event Log file).

This means that if you click “Open” on any of these files in WhatsApp, they will execute immediately, including any malicious code. But there’s a catch—for this to happen, you need to install Python on your computer, which few people do.

Limited impact

According to BleepingComputer, the requirement to have Python installed limits the targets for software developers, researchers, and power users. Das reported the issue to Meta in early June 2024 and received a response a month and a half later. Meta acknowledged the problem but indicated it had been reported before and stated they wouldn’t address it.

In a statement to BleepingComputer, Meta explained that it’s the user’s responsibility to avoid opening malicious files. “We’ve read what the researcher has proposed and appreciate their submission. Malware can take many forms, including through downloadable files meant to trick a user,” the statement reads. “It’s why we warn users to never click on or open a file from somebody they don’t know, regardless of how they received it—whether over WhatsApp or any other app.”

User responsibility

Meta’s stance is clear: users must stay vigilant and avoid opening files from unknown sources. This advice is essential for maintaining digital safety on WhatsApp and across all platforms and applications. Always be cautious with the files you download and open, and ensure you have the necessary security measures to protect your system.

The flaw in WhatsApp for Windows serves as a reminder of the importance of digital hygiene and being aware of the files you interact with online. While Meta might not fix this issue, staying informed and cautious can help you avoid potential threats and secure your computer.

Hot this week

Apple delays launch of smarter Siri, leaving AI fans waiting

Apple will delay AI-powered Siri until 2026 as WWDC 25 skips the update and focuses instead on other AI features and improvements.

Commvault strengthens data protection with post-quantum cryptography capabilities

Commvault expands post-quantum cryptography support with HQC to protect long-term data from future quantum computing threats.

NTT DATA and Booz Allen Hamilton partner to boost cybersecurity in Singapore

NTT DATA and Booz Allen Hamilton sign MOU to enhance cybersecurity in Singapore and the Indo-Pacific, focusing on AI, threat detection, and research.

Qualcomm to buy UK chipmaker Alphawave Semi for US$2.4 billion

Qualcomm will buy UK-based Alphawave Semi for US$2.4B to boost its data centre tech and expand beyond smartphone chips.

Apple’s visionOS 26 brings spatial widgets, lifelike avatars, and shared experiences

Apple’s visionOS 26 update brings spatial widgets, improved avatars, and shared headset experiences for a more immersive digital world.

Hong Kong opens skies to larger drones in bid to grow low-altitude economy

Hong Kong will allow the testing of larger drones to boost its low-altitude economy and improve logistics, following mainland China's lead.

Hong Kong to build new AI supercomputing centre in bid to lead global tech race

Hong Kong plans a new AI supercomputing centre to boost its tech hub status and support growing start-ups across the Greater Bay Area.

Steam adds full native support for Apple Silicon Macs

Steam runs natively on Apple Silicon Macs, ditching Rosetta 2 for smoother performance and better gaming on M1 and M2 devices.

Amazon taps nuclear power to boost AWS cloud energy supply

Amazon signs a 1.92 GW nuclear energy deal with Talen to power AWS cloud and explore new small modular reactors in Pennsylvania.

Related Articles

Popular Categories