4 ms·
Agreed. It seems more plausible that the "injected code" would be limited to (1) the WhatsApp app, and (2) the infrastructure outside of the Signal Protocol imp
by cottsak 7y ago
Agreed. It seems more plausible that the "injected code" would be limited to (1) the WhatsApp app, and (2) the infrastructure outside of the Signal Protocol implementation. If true, this still poses a problem to comms/calls secured end-to-end with the Signal Protocol impl - because once decrypted on the client, the rest of the WhatsApp may be compromised and able to exfil comms.
I will be surprised, if this vuln allows the attacker control outside of the WhatsApp app sandbox to other parts of iOS.
(I will be less surprised if the above is possible in Android)