Vulnerabilities in WhatsApp Web affect 200 million users globally
Found on Net Security on Tuesday, 08 September 2015
Check Point security researcher Kasif Dekel found that to exploit the vulnerability, an attacker simply needs to send a WhatsApp user a seemingly innocent vCard contact card, containing malicious code. Once opened in WhatsApp Web, the executable file in the contact card can run, further compromising computers by distributing malware including ransomware, bots, remote access tools (RATs), and other types of malicious code.
Starting executables from unknown and random sources should have stopped a decade ago already.