The Register Home Page

back to article WhatsApp warns of 'attack against specific targeted users'

A flaw in Meta's WhatsApp app “may have been exploited in a sophisticated attack against specific targeted users.” Meta made that alarming admission last week in a security advisory that disclosed CVE-2025-55177, which it described as allowing “Incomplete authorization of linked device synchronization messages in WhatsApp [ …

  1. blu3b3rry Silver badge
    Mushroom

    While using MFA is a good thing....

    I've never quite wrapped my head around why M$'s implementation of it is so rubbish and user-unfriendly.

    I use MFA on a few different accounts. Google accounts just ping my phone with a "yes/no" message or can be given a passkey when that service isn't working. Fair enough although a code would be better.

    Proton uses either their own authenticator app or a third-party one that generates you a six-digit code to type in at login. Both of these allow access to all account services once login is complete.

    M$? For some reason the PC gives you a two-digit code to type into the phone, although have fun waiting for the M$ authenticator phone app to realise it needs to display the input prompt.

    Heavens forbid you open two bits of Windows software, say Outlook and Teams that both require authentication at once.

    They both generate unique two-digit codes but the authenticator app isn't bright enough to tell you which app is requesting the authentication. The login also doesn't cross-pollinate across the two programs or even onto the OS, so when this does occur you have to go through the rigmarole again.

    Can you tell I've not had a coffee yet?

    1. UK DM

      Re: While using MFA is a good thing....

      Custom apps wanting 2 digit codes and MFA standard authenticators are good but there are headaches with the more basic systems.

      Isn't there meant to be a security standard for sending codes to mobiles (via messaging like SMS) such that a locked phone (even with message preview enabled) can not be used to see the code by an attacker that has simply stolen the phone.

      The idea seemed to be the message preview function does not show enough of the message to flash up the code. As the code should be towards the end of the message.

      While I have seen such a standard written down somewhere I have trouble finding a large vendor that implements it.

      So have to use all previews disabled when locked setting.

      Maybe the vendor see the problem as the account holder's risk and not their risk. So convienence wins from customer feedback from the masses who think security is someone else's problem.

      I also tried to explain to UK Vodafone support that I would like at least a 3 day cool off for a SIM swap (meaning my service to the UK number for this minimum mandated outage period, if it was performed unplanned/without sufficient notice/adhoc).

      Can we hope they at least send SMS message sent immediately and again an hour before the old SIM was disconnected to inform the old phone and SIM was being disconnected and to contact customer services if this was unexpected. To help mitigate SIM swap fraud. Hopefully they do this now.

    2. IGotOut Silver badge

      Re: While using MFA is a good thing....

      Its just more ways to lock you into the MS ecosystem.

      Luckily I don't use MS, so I use Aegis for 13 different accounts no problem, backing up to nextcloud.

      MS...nah, we want you to use our app for "security"

  2. Anonymous Coward
    Anonymous Coward

    WhatsApp

    Ahhhh yes.

    Digital shite.

POST COMMENT House rules

Not a member of The Register? Create a new account here.

  • Enter your comment

  • Add an icon

Anonymous cowards cannot choose their icon

Other stories you might like