Skype crashes after specific 8-char string is received in chat, updates released with fix
These 8 characters crash Skype, and once they're in your chat history, the app can't start (Update: fixed) — Skype users have discovered a rather nasty bug in the app.
Context & Ripple Effects
Skype's fix lands one week after Apple scrambled over its own iOS Messages crash bug, where a single text string rebooted iPhones — and that variant quickly spread through Snapchat chats and Twitter DMs. The two bugs share a shape: a short, attacker-chosen payload that kills the client on receipt, then keeps killing it because the message sits in local history.
For Skype the stakes were higher than a reboot — the app wouldn't start at all once the string was stored — making it a denial-of-service that outlives the message itself. It also fits a longer pattern for the client: three years later, Skype's update installer was still exposed to DLL hijacking giving system-level privileges, a flaw Microsoft said would only be fixed by rewriting the app.
First-order effects
- Users who received the 8-character string lose access to Skype entirely until they get an updated build, since the corrupted chat history prevents launch.
- Microsoft has to ship fixes across every affected Skype platform simultaneously — any lagging platform leaves those users locked out.
Second-order effects
- Every mainstream messaging client now has to audit how it renders inbound text before persisting it, since WhatsApp later faced the same class of failure when a rogue group member could make the app unusable and force a reinstall that destroyed group chat content.
- The persistence problem pushes vendors toward sanitizing or quarantining messages server-side rather than trusting the client to survive whatever arrives.
Third-order effects
- Chat apps converge on treating all inbound content as hostile input at render time, because a crash-on-receipt bug doubles as a permanent denial-of-service once it enters history.
- Repeated client-level flaws in long-lived codebases like Skype's strengthen the case Microsoft eventually took — rewriting the application rather than patching it, as it did with the version 8 rewrite that carried the DLL-hijacking fix.
The trend: Messaging platforms are learning that untrusted user-supplied strings must be treated as adversarial input everywhere — display, storage, and notification — because a single bad payload can take a client down permanently.