Nobody, My Contacts (people whose phone numbers they have saved in their phone), and Everyone
The messaging app has added that a new privacy setting in which an invite system will help users decide who can add them to groups. Previously, WhatsApp users could be added to groups without their consent.
To enable the feature, users can go to 'settings' option in WhatsApp app and select one of three options -- nobody, my contacts, or everyone. If they choose nobody, users will have to approve joining every group to which they are invited.
Upon choosing my contacts option, users from the person's address book will be able to add them to groups. In these cases, the person inviting you to a group will be prompted to send a private invite through an individual chat, giving the user choice of joining the group.
The user will be given three days to accept the invite before it expires, the statement said. "With these new features, users will have more control over the group messages they receive," WhatsApp said.
These new privacy settings will begin rolling out to some users starting Wednesday, and will be available worldwide in the coming weeks to those using the latest version of WhatsApp, it added.
A security flaw in WhatsApp can be, and has been, exploited to inject spyware into victims' smartphones: all a snoop needs to do is make a booby-trapped voice call to a target's number, and they're in. The victim doesn't need to do a thing other than leave their phone on.
The Facebook-owned software suffers from a classic buffer overflow weakness. This means a successful hacker can hijack the application to run malicious code that pores over encrypted chats, eavesdrops on calls, turns on the microphone and camera, accesses photos, contacts, and other information on a handheld, and potentially further compromises the device. Call logs can be altered, too, to hide the method of infection.
Description: A buffer overflow vulnerability in WhatsApp VOIP stack allowed remote code execution via specially crafted series of SRTCP packets sent to a target phone number.