Close Menu
Xarkas BlogXarkas Blog
    What's Hot

    Redmi Note 15 Series Launch in India Tipped to Take Place in December: Sale Will Commence in January 2026

    November 15, 2025

    How to Customize Your Character in Where Winds Meet

    November 15, 2025

    Oura Ring 4 Ceramic review: A colorful glow-up

    November 15, 2025
    Facebook X (Twitter) Instagram
    Xarkas BlogXarkas Blog
    • Tech News

      Oura Ring 4 Ceramic review: A colorful glow-up

      November 15, 2025

      Tesla releases detailed safety report after Waymo co-CEO called for more data

      November 15, 2025

      Everything you need to know about the AI chatbot

      November 15, 2025

      A comprehensive list of 2025 tech layoffs

      November 15, 2025

      Leaked documents shed light into how much OpenAI pays Microsoft

      November 15, 2025
    • Mobiles

      Redmi Note 15 Series Launch in India Tipped to Take Place in December: Sale Will Commence in January 2026

      November 15, 2025

      OPPO Unveils Apex Guard to Redefine Smartphone Quality and Longevity

      November 15, 2025

      Philips Smartphone Officially Teased in India: Philips Pad Air Specifications Surface Online

      November 15, 2025

      Samsung Galaxy S26 Series Camera Specifications Tipped Ahead of Launch

      November 15, 2025

      OnePlus 15 Review: The Power and Speed are Back, But at a Cost

      November 15, 2025
    • Gaming

      How to Customize Your Character in Where Winds Meet

      November 15, 2025

      Damaged Heat Sink Locations In ARC Raiders

      November 15, 2025

      City Status (Level) Guide In Anno 117 Pax Romana

      November 15, 2025

      Final Fantasy 14’s 7.4 Update Includes Extra Change To Controversial Feature

      November 15, 2025

      Should You Spare or Kill Shroud in Dispatch Episode 8?

      November 15, 2025
    • SEO Tips
    • PC/ Laptops

      Apple Reportedly Reserving OLED Displays for M6 Pro and M6 Max MacBook Pro Models

      November 10, 2025

      Apple Reportedly Working on a Budget MacBook Featuring iPhone Chip: Expected Launch and Price

      November 5, 2025

      Acer Predator Helios Neo 16 AI and 16S AI Gaming Laptops Launched in India: Check Pricing and Specifications

      November 4, 2025

      COLORFUL Launches Rimbook L1: Affordable Laptop For Everyday Use

      November 4, 2025

      Acer Expands Lite Series With New Nitro Lite 16 Laptop in India

      November 3, 2025
    • EV

      Here’s How Much It Costs

      November 15, 2025

      Sodium-Ion Batteries Have Landed In America. The Hard Part Starts Now

      November 15, 2025

      Mazda Begins Testing Its Long-Overdue U.S. EV

      November 14, 2025

      Volkswagen Adds Smartwatch Support For U.S. Vehicles

      November 14, 2025

      TATA.ev expands charging footprint with 14 new manned MegaChargers across AP, Telangana

      November 14, 2025
    • Gadget
    • AI
    Facebook
    Xarkas BlogXarkas Blog
    Home - Featured - WhatsApp for Windows Security Flaw Allows Executing Python, PHP Files Without Warning: Report
    Featured

    WhatsApp for Windows Security Flaw Allows Executing Python, PHP Files Without Warning: Report

    KavishBy KavishAugust 23, 2024No Comments3 Mins Read
    Facebook Twitter Pinterest Telegram LinkedIn Tumblr WhatsApp Email
    WhatsApp for Windows Security Flaw Allows Executing Python, PHP Files Without Warning: Report
    Share
    Facebook Twitter LinkedIn Pinterest Telegram Email


    WhatsApp for Windows reportedly has a vulnerability that can be exploited by bad actors. The security flaw exploits executable files of Python and PHP for which the app does not send a warning, claimed the report. As a result, an unsuspecting user might accidentally save and run the file, allowing the attacker to deploy the payload. WhatsApp reportedly has refused to take any action citing the problem is not at their end, and that it already warns users to not download files from unknown senders.

    WhatsApp for Windows Reportedly Has a Security Flaw

    According to a report by Bleeping Computer, the vulnerability was found in the latest version of the WhatsApp for Windows app. It is said to allow users to send Python and PHP attachments in executable format. The files, when being downloaded at the recipient’s end, does not result in a warning notification from the instant messaging platform.

    The security flaw was discovered by cybersecurity firm Zeron’s security researcher Saumyajeet Das. As per the report, WhatsApp in most cases does not allow launching potentially harmful files such as .EXE. While the user may see options of Open or Save As, clicking on Open generates an error. The user may still save the file on the device and launch it, but the warning acts as a reminder of the malicious nature of the file. This behaviour is said to be consistent for file formats such as .EXE, .COM, .SCR, .BAT, and Perl.

    However, the researcher reportedly found that three file types — .PYZ (Python ZIP app), .PYZW (PyInstaller program), and .EVTX (Windows event Log file) — did not trigger the error warning and users can open the file and launch them directly from within the app. Further, the publication found the same exception existed for PHP files.

    Notably, an attack conducted using these file types will not be successful unless the user has Python installed in their system. This reduces vulnerable users to software developers, researchers, and others who code on their system.

    The publication claims that Das reported the issue via Meta’s bug bounty programme on June 3. But on July 15, the company replied that the same issue was previously reported by another researcher. The issue is still not fixed, as per the report, and it was said to be present in the latest WhatsApp for Windows 11 version v2.2428.10.0.

    A WhatsApp spokesperson told the publication, “We’ve read what the researcher has proposed and appreciate their submission. Malware can take many different forms, including through downloadable files meant to trick a user. It’s why we warn users to never click on or open a file from somebody they don’t know, regardless of how they received it — whether over WhatsApp or any other app.”



    Source link

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Kavish
    • Website

    Related Posts

    Redmi Note 15 Series Launch in India Tipped to Take Place in December: Sale Will Commence in January 2026

    November 15, 2025

    How to Customize Your Character in Where Winds Meet

    November 15, 2025

    Oura Ring 4 Ceramic review: A colorful glow-up

    November 15, 2025

    Tesla releases detailed safety report after Waymo co-CEO called for more data

    November 15, 2025

    OPPO Unveils Apex Guard to Redefine Smartphone Quality and Longevity

    November 15, 2025

    Damaged Heat Sink Locations In ARC Raiders

    November 15, 2025

    Comments are closed.

    Top Reviews
    Editors Picks

    Redmi Note 15 Series Launch in India Tipped to Take Place in December: Sale Will Commence in January 2026

    November 15, 2025

    How to Customize Your Character in Where Winds Meet

    November 15, 2025

    Oura Ring 4 Ceramic review: A colorful glow-up

    November 15, 2025

    Tesla releases detailed safety report after Waymo co-CEO called for more data

    November 15, 2025
    About Us
    About Us

    Email Us: info@xarkas.com

    Facebook Pinterest
    © 2025 . Designed by Xarkas Technologies.
    • Home
    • Mobiles
    • Privacy Policy

    Type above and press Enter to search. Press Esc to cancel.

    Ad Blocker Enabled!
    Ad Blocker Enabled!
    Our website is made possible by displaying online advertisements to our visitors. Please support us by disabling your Ad Blocker.