Check Point says critical vulnerability found in Instagram, issue fixed

Check Point added that the patch for this vulnerability has already been available for six months now

Check Point says critical vulnerability found in Instagram, issue fixed
Check Point also noted that it had disclosed its findings to Facebook and the Instagram team.
Press Trust of India New Delhi
2 min read Last Updated : Sep 24 2020 | 9:18 PM IST
Security firm Check Point on Thursday said its researchers had found a vulnerability on the Instagram app that could have allowed an attacker to take over a victim's account using a malicious image - an issue which has now been fixed.
 
Earlier this year, Check Point researchers had found a critical vulnerability in the Instagram app that would have given an attacker the ability to take over a victim's Instagram account, and turn their phone into a spying tool by sending them a malicious image file, Check Point said in a statement.
 
When the image is saved and opened in the Instagram app, the exploit would have given the hacker full access to the victim's Instagram messages and images, allowing them to post or delete images at will, as well as giving access to the phone's contacts, camera and location data, it added.

ALSO READ: Facebook being sued for allegedly spying on Instagram users, again
 
When contacted, a Facebook spokesperson said: "Check Point's report overstates a bug, which we fixed quickly and have no reason to believe impacted anyone. Through their own investigation Check Point was unable to successfully exploit this bug."
 
Check Point also noted that it had disclosed its findings to Facebook and the Instagram team.
 
"Facebook's advisory was very responsive and helpful, they have described this vulnerability as an 'Integer Overflow leading to Heap Buffer Overflow' and issued a patch to remediate the issue on the newer versions of the Instagram application on all platforms," it said.
 
Check Point added that the patch for this vulnerability has already been available for six months now, giving time to the majority of users to update their Instagram app, thus mitigating the risk of this vulnerability being exploited.
 
"We strongly encourage all Instagram users to ensure they are using the latest Instagram app version and to update if any new version is available," it said.

One subscription. Two world-class reads.

Already subscribed? Log in

Subscribe to read the full story →
*Subscribe to Business Standard digital and get complimentary access to The New York Times

Smart Quarterly

₹900

3 Months

₹300/Month

SAVE 25%

Smart Essential

₹2,700

1 Year

₹225/Month

SAVE 46%
*Complimentary New York Times access for the 2nd year will be given after 12 months

Super Saver

₹3,900

2 Years

₹162/Month

Subscribe

Renews automatically, cancel anytime

Here’s what’s included in our digital subscription plans

Exclusive premium stories online

  • Over 30 premium stories daily, handpicked by our editors

Complimentary Access to The New York Times

  • News, Games, Cooking, Audio, Wirecutter & The Athletic

Business Standard Epaper

  • Digital replica of our daily newspaper — with options to read, save, and share

Curated Newsletters

  • Insights on markets, finance, politics, tech, and more delivered to your inbox

Market Analysis & Investment Insights

  • In-depth market analysis & insights with access to The Smart Investor

Archives

  • Repository of articles and publications dating back to 1997

Ad-free Reading

  • Uninterrupted reading experience with no advertisements

Seamless Access Across All Devices

  • Access Business Standard across devices — mobile, tablet, or PC, via web or app

Topics :InstagramSocial Media

Next Story