16.1 C
Delhi
Thursday, November 20, 2025

WhatsApp Security Flaw Exposed 3.5 Billion Phone Numbers

Key Takeaways

  • WhatsApp security flaw exposed 3.5 billion phone numbers to potential data scraping
  • Researchers accessed profile photos (57% of cases) and profile text (29% of users)
  • Vulnerability existed despite 2017 warnings; fixed with rate-limiting in October 2025
  • Meta confirms no evidence of malicious exploitation; messages remained encrypted

A massive security vulnerability in WhatsApp put approximately 3.5 billion user phone numbers at risk of exposure, according to University of Vienna researchers. The flaw could have become “the largest data leak in history” if exploited by malicious actors.

Security experts found they could access not just phone numbers but also profile photos for 57% of users and profile text information for 29% of accounts. The potential breach would have eclipsed Facebook’s 2021 scraping incident involving 500 million records.

Aljosha Judmayer, one of the study researchers, told WIRED: “To the best of our knowledge, this marks the most extensive exposure of phone numbers and related user data ever documented.”

Notably, WhatsApp and parent company Meta had been alerted about similar vulnerabilities as early as 2017 but failed to take adequate action at that time.

How the WhatsApp Security Flaw Worked

The vulnerability existed in WhatsApp’s contact discovery feature, which normally helps users find contacts already on the platform. Researchers discovered that without effective rate-limiting, this feature could be exploited to scan massive ranges of phone numbers.

Once a number was confirmed as active on WhatsApp, the same method could retrieve publicly available information including:

  • Profile pictures
  • Profile about text
  • Device types
  • Linked companion devices

Meta’s Response and Fix

Meta acknowledged the security issue and collaborated with researchers after they reported it through the Bug Bounty program in April 2025. The company implemented stricter rate-limiting measures by October 2025 to prevent such scraping attacks.

A Meta spokesperson stated: “We are grateful to the University of Vienna researchers for their responsible partnership. This collaboration successfully identified a novel enumeration technique that surpassed our intended limits.”

The company emphasized that user messages remained secure due to WhatsApp’s default end-to-end encryption, and researchers have securely deleted all collected data. Meta confirmed finding no evidence of malicious actors exploiting this vulnerability.

Latest

Roblox Implements Facial Age Verification to Protect Children from Adults

Roblox becomes first gaming platform to require facial age checks for chat features, grouping users by age to prevent child-adult interactions amid safety concerns.

Microsoft 365 Copilot Gets AI Agents for Word, Excel, PowerPoint

Microsoft Ignite 2025 reveals AI agents that create documents, spreadsheets, and presentations through natural language commands in Copilot Chat with enhanced security.

Robot Dog Spot Joins 60+ Bomb Squads at Rs 90 Lakh Cost

Boston Dynamics' Spot robot now serves over 60 police departments for bomb disposal and rescue missions, priced from $100,000. Learn about its capabilities and the ethical debate.

Google Gemini 3 Launches in India with Free Jio Access Plan

Get 18 months of Google's advanced Gemini 3 AI free with Jio Unlimited 5G. Learn features and how to claim the Rs 35,100 package.

Google Play Store Awards 2025: Best Apps and Games in India

Discover the top award-winning apps and games on Google Play Store in India for 2025, including AI-powered tools and locally relevant content.

Topics

Epstein Files to Be Released Within 30 Days, Says AG Bondi

US Justice Department will disclose Jeffrey Epstein investigation documents after Congress forces transparency, potentially revealing connections with powerful figures.

ISL Tender Crisis: SC Panel Urges Balance After AIFF Bid Failure

Justice Rao recommends financial and governance reforms after AIFF receives zero bids for ISL commercial rights, as 12 clubs move Supreme Court over livelihood concerns.

Vapes 3,000 Times Dirtier Than Toilet Seats, Study Reveals

Laboratory research shows vape mouthpieces harbour dangerous bacteria and fungi. Learn proper cleaning methods to reduce health risks.

Trump and Ronaldo’s ‘Two GOATs’ Moment at White House Dinner

Exclusive video shows Donald Trump and Cristiano Ronaldo sharing a friendly moment at White House state dinner with world leaders and tech billionaires.

Gates Foundation Sells 65% of Microsoft Stake in Major Portfolio Shift

Gates Foundation's Q3 2025 portfolio rebalancing cuts Microsoft stake by 65%, reduces holdings from 25 to 23, and drops portfolio value by $11.2 billion.

Bill Ackman Reveals $300 Billion Plan for Fannie Mae and Freddie Mac Reform

Billionaire investor Bill Ackman proposes three-step $300 billion plan to relist Fannie Mae and Freddie Mac, creating taxpayer value while meeting Trump administration timeline.

AMD, Cisco and Saudi’s Humain Launch AI Data Center Venture with Luma AI as First Client

Major tech partnership to build AI data centers in Middle East, with Luma AI securing entire 100-megawatt capacity in first project targeting 4.5 billion people.

Veefin Appoints Sorabh Dhawan as CEO of PSB Xchange Platform

Sorabh Dhawan to lead PSB Xchange's digital transformation, bringing 18 years of banking expertise to enhance India's supply chain finance ecosystem.
spot_img

Related Articles

Popular Categories

spot_imgspot_img