Check Point says critical vulnerability found in Instagram, issue fixed

Check Point added that the patch for this vulnerability has already been available for six months now

Topics
Instagram | Social Media

Press Trust of India  |  New Delhi 

Instagram, social media, apps
Check Point also noted that it had disclosed its findings to Facebook and the Instagram team.

Security firm Check Point on Thursday said its researchers had found a vulnerability on the app that could have allowed an attacker to take over a victim's account using a malicious image - an issue which has now been fixed.

Earlier this year, Check Point researchers had found a critical vulnerability in the app that would have given an attacker the ability to take over a victim's account, and turn their phone into a spying tool by sending them a malicious image file, Check Point said in a statement.

When the image is saved and opened in the Instagram app, the exploit would have given the hacker full access to the victim's Instagram messages and images, allowing them to post or delete images at will, as well as giving access to the phone's contacts, camera and location data, it added.


When contacted, a Facebook spokesperson said: "Check Point's report overstates a bug, which we fixed quickly and have no reason to believe impacted anyone. Through their own investigation Check Point was unable to successfully exploit this bug."

Check Point also noted that it had disclosed its findings to Facebook and the Instagram team.

"Facebook's advisory was very responsive and helpful, they have described this vulnerability as an 'Integer Overflow leading to Heap Buffer Overflow' and issued a patch to remediate the issue on the newer versions of the Instagram application on all platforms," it said.

Check Point added that the patch for this vulnerability has already been available for six months now, giving time to the majority of users to update their Instagram app, thus mitigating the risk of this vulnerability being exploited.

"We strongly encourage all Instagram users to ensure they are using the latest Instagram app version and to update if any new version is available," it said.

Dear Reader,


Business Standard has always strived hard to provide up-to-date information and commentary on developments that are of interest to you and have wider political and economic implications for the country and the world. Your encouragement and constant feedback on how to improve our offering have only made our resolve and commitment to these ideals stronger. Even during these difficult times arising out of Covid-19, we continue to remain committed to keeping you informed and updated with credible news, authoritative views and incisive commentary on topical issues of relevance.
We, however, have a request.

As we battle the economic impact of the pandemic, we need your support even more, so that we can continue to offer you more quality content. Our subscription model has seen an encouraging response from many of you, who have subscribed to our online content. More subscription to our online content can only help us achieve the goals of offering you even better and more relevant content. We believe in free, fair and credible journalism. Your support through more subscriptions can help us practise the journalism to which we are committed.

Support quality journalism and subscribe to Business Standard.

Digital Editor

Read our full coverage on Instagram
First Published: Thu, September 24 2020. 20:52 IST
RECOMMENDED FOR YOU
RECOMMENDED FOR YOU