Some follow up to the WhatsApp MCP attack demonstration.
Turns out it is enough to send an injection to your target's WhatsApp account, so no need to install bad MCP servers.
It's (indirect) prompt injection, and not exclusive to MCP.
More 👇
Crowdstrike Analysis:
It was a NULL pointer from the memory unsafe C++ language.
Since I am a professional C++ programmer, let me decode this stack trace dump for you.
Since I can’t format a thread to save my life, here’s my previous thread on Apple’s Private Cloud Compute in threadreader form. https://t.co/0nBqJUFDv0