Researchers detected a critical RCE Instagram vulnerability that allows the threat actors to take control of your Instagram account by sending a simple images to the victim via email, WhatsApp or other media exchange platforms. When the victim opens the Instagram app, the exploitation takes place.
We all know that Instagram is one of the most widespread social networks in the world, as it has more than 100 million photos uploaded daily, and almost 1 billion monthly active users. That’s why, for the threat actors, Instagram is one of the most lucrative targets.
However, the Check Point researchers revealed all the details regarding this critical vulnerability in Instagram’s Android and iOS app that could have enabled the remote attackers to take control over a targeted device by transferring a specially crafted image to the victims.
A crucial vulnerability that might enable the threat actors is technically assigned to remote code execution (RCE). This kind of exposure can allow the threat actors to implement any operation they wish to implement in the Instagram app.
We all know that the Instagram app has extensive acceptance, enabling the threat actors to immediately turn the victim’s phones into a whole spying tool – placing the privacy of millions of users at high risk.
The experts asserted that the vulnerability is a packet of buffer overflow (CVE-2020-1895) befalling when Instagram decided to upload a more comprehensive image considering it to be smaller. However, Facebook has fixed the problem in springtime, following the compelled disclosure from cybersecurity company Check Point, and issued a hazy security announcement for it.
Gal Elbaz from Check Point highlights how a custom implementation of third-party code on Instagram could have directed to a dangerous, remote code execution uncertainties.
But the weak point in this procedure is that the hardcoded consistent value that Instagram developers attached while combining Mozjpeg. It’s an open-source JPEG encoder that Mozilla branch from libjpeg-turbo for better concentration of JPEG images.
A possible situation from the threat actors with skills to exploit the glitch are mentioned below:-
Mitigations that are to be followed by the users to keep themselves safe and secure:-
Security experts are still investigating this whole matter and affirmed that they would provide every detail regarding this vulnerability. Till then, they requested all the users to perform every mitigation that they have provided, as it will help the users to keep themselves safe and secure.
You can follow us on Linkedin, Twitter, Facebook for daily Cyber security and hacking news updates.
Also Read:
MFA Bypass Bugs Would Allows Hackers to Access Office 365 Accounts
New Raccoon Attack Allow Hackers to Break SSL/TLS Encryption
Hackers are actively probing AI systems, turning exposed gateways and agent tools into routes for…
Hackers are making some phishing pages harder to track by changing the code delivered to…
A cyber incident reportedly forced a British power plant to halt operations for about four…
Russian hackers have used a new backdoor called HOOKEDGE to target defense manufacturers, government bodies,…
TITAN ransomware is pairing file encryption with an ambitious claim: artificial intelligence that can sort…
A fake student resume is being used to place a remote-access tool on researchers’ Windows…