WhatsApp urges users to upgrade app after report of spyware attack

Published May 14, 2019
The Financial Times reported that a vulnerability in WhatsApp allowed attackers to inject spyware on phones by ringing up targets using the app's phone call function. — AFP
The Financial Times reported that a vulnerability in WhatsApp allowed attackers to inject spyware on phones by ringing up targets using the app's phone call function. — AFP

Facebook's WhatsApp on Tuesday urged users to upgrade to the latest version of its popular messaging app following a report that users could be vulnerable to having malicious spyware installed on phones without their knowledge.

"WhatsApp encourages people to upgrade to the latest version of our app, as well as keep their mobile operating system up to date, to protect against potential targeted exploits designed to compromise information stored on mobile devices," a spokesman said.

"We are constantly working alongside industry partners to provide the latest security enhancements to help protect our users."

The Financial Times reported that a vulnerability in WhatsApp allowed attackers to inject spyware on phones by ringing up targets using the app's phone call function. It said the spyware was developed by Israeli cyber surveillance company NSO Group.

Asked about the report, NSO said its technology is licensed to authorised government agencies "for the sole purpose of fighting crime and terror," and that it does not operate the system itself.

"We investigate any credible allegations of misuse and if necessary, we take action, including shutting down the system. Under no circumstances would NSO be involved in the operating or identifying of targets of its technology, which is solely operated by intelligence and law enforcement agencies," the company said.

"NSO would not or could not use its technology in its own right to target any person or organisation, including this individual."

Highly invasive software

The WhatsApp spyware is sophisticated and "would be available to only advanced and highly motivated actors", the company said, adding that a "select number of users were targeted".

"This attack has all the hallmarks of a private company that works with a number of governments around the world" according to initial investigations, it added, but did not name the firm.

WhatsApp has briefed human rights organisations on the matter, but did not identify them.

The Citizen Lab, a research group at the University of Toronto, said in a tweet it believed an attacker tried to target a human rights lawyer as recently as Sunday using this flaw, but was blocked by WhatsApp.

The NSO Group came to prominence in 2016 when researchers accused it of helping spy on an activist in the United Arab Emirates. Its best-known product is Pegasus, a highly invasive tool that can reportedly switch on a target's phone camera and microphone, and access data on it.

Opinion

Editorial

Doctor attacked
09 Jun, 2026

Doctor attacked

AN act of reprehensible violence has shaken the medical community. On Saturday, an employee of the Provincial Civil...
AJK flare-up
09 Jun, 2026

AJK flare-up

MATTERS have worsened in the stand-off between the Azad Kashmir government and the Joint Awami Action Committee,...
Fault lines
09 Jun, 2026

Fault lines

THE April 8 ceasefire that halted hostilities between Israel and Iran has encountered its most serious test yet....
Soft on traders
08 Jun, 2026

Soft on traders

THE Fixed Tax Asaan Scheme for traders with an annual turnover of up to Rs200m has been designed as a ‘pragmatic...
Ceasefire in name
Updated 08 Jun, 2026

Ceasefire in name

Both sides accuse the other of violating the truce that was supposed to halt the conflict in April, yet neither appears willing to abandon negotiations altogether.
Damaged childhoods
08 Jun, 2026

Damaged childhoods

CHILD abuse is so prevalent that the UN ranked Pakistan as the least safe country for children. Even so, more than...