The Sri Lanka Computer Emergency Readiness Team (Sri Lanka CERT) has warned of a new cyberattack targeting WhatsApp accounts of Apple iPhone users.
According to Sri Lanka CERT, the attack, known as a “zero-click” attack, is believed to exploit security vulnerabilities in iPhones running iOS 16.
Sri Lanka CERT said several individuals affected by the attack have already lodged complaints, confirming that the zero-click WhatsApp security breach is occurring in Sri Lanka.
The agency said researchers at an Italian cybersecurity firm have identified several vulnerabilities that may be exploited together to target WhatsApp’s Linked Device Synchronization process, allowing attackers to gain unauthorized access to accounts.
Some victims have reported discovering unauthorized messages sent from their WhatsApp accounts requesting money from their contacts, despite finding no suspicious changes in their account settings.
Sri Lanka CERT has urged iPhone users to immediately update their devices to the latest available iOS version and install the latest WhatsApp update.
Users have also been advised to enable WhatsApp’s Two-Step Verification and Chat Lock features.
Sri Lanka CERT further urged users to independently verify any unusual requests for money through a trusted alternative communication channel before taking action.