#WhatsApp for #Windows lets Python, PHP scripts execute with no warning

Granted, Python needs to be installed on the system prior.

Meta says they will not bother to fix this, despite maintaining a built-in list of potentially dangerous file types (ex: .exe)

#security #cybersecurity #messengers

bleepingcomputer.com/news/secu…

in reply to Avoid the Hack!

@xogium oddly the same story goes for accessibility-related things, so this is an area in which security and accessibility can intersect in a strange way, too. Until there's mass-exploitation of this (and it's a bit limited of course with requiring Python to be in path to begin with), they may never get to it, it'll stay in Backlog for months, get punted to another team, go to their backlog, maybe a spike gets created over it, yada yada yada