The Public Security Police (PSP) has issued an alert regarding a new type of cyberattack that can compromise WhatsApp accounts on iPhones without any user interaction. This 'zero-click' attack exploits vulnerabilities in the operating system and the app to link the victim's account to another device, allowing criminals to send fraudulent messages.
The danger lies in the fact that malicious activity may go undetected by the victim, who can continue using the app normally while attackers send messages, for instance, requesting money. These flaws can affect Apple devices with outdated operating system versions, specifically iOS versions prior to 16.7.12, in conjunction with WhatsApp-specific vulnerabilities.
To mitigate the risk, the PSP and tech companies recommend keeping the operating system and WhatsApp updated, enabling two-step verification, regularly checking the list of associated devices, and terminating unrecognized sessions.
