5.1 C
Delhi
Friday, January 16, 2026

WhatsApp Security Flaw Exposed 3.5 Billion Phone Numbers

Key Takeaways

  • WhatsApp security flaw exposed 3.5 billion phone numbers to potential data scraping
  • Researchers accessed profile photos (57% of cases) and profile text (29% of users)
  • Vulnerability existed despite 2017 warnings; fixed with rate-limiting in October 2025
  • Meta confirms no evidence of malicious exploitation; messages remained encrypted

A massive security vulnerability in WhatsApp put approximately 3.5 billion user phone numbers at risk of exposure, according to University of Vienna researchers. The flaw could have become “the largest data leak in history” if exploited by malicious actors.

Security experts found they could access not just phone numbers but also profile photos for 57% of users and profile text information for 29% of accounts. The potential breach would have eclipsed Facebook’s 2021 scraping incident involving 500 million records.

Aljosha Judmayer, one of the study researchers, told WIRED: “To the best of our knowledge, this marks the most extensive exposure of phone numbers and related user data ever documented.”

Notably, WhatsApp and parent company Meta had been alerted about similar vulnerabilities as early as 2017 but failed to take adequate action at that time.

How the WhatsApp Security Flaw Worked

The vulnerability existed in WhatsApp’s contact discovery feature, which normally helps users find contacts already on the platform. Researchers discovered that without effective rate-limiting, this feature could be exploited to scan massive ranges of phone numbers.

Once a number was confirmed as active on WhatsApp, the same method could retrieve publicly available information including:

  • Profile pictures
  • Profile about text
  • Device types
  • Linked companion devices

Meta’s Response and Fix

Meta acknowledged the security issue and collaborated with researchers after they reported it through the Bug Bounty program in April 2025. The company implemented stricter rate-limiting measures by October 2025 to prevent such scraping attacks.

A Meta spokesperson stated: “We are grateful to the University of Vienna researchers for their responsible partnership. This collaboration successfully identified a novel enumeration technique that surpassed our intended limits.”

The company emphasized that user messages remained secure due to WhatsApp’s default end-to-end encryption, and researchers have securely deleted all collected data. Meta confirmed finding no evidence of malicious actors exploiting this vulnerability.

Latest

Meta Bans ChatGPT on WhatsApp from 2026: How to Save Chats

WhatsApp will block ChatGPT and third-party AI tools in 2026. Learn why Meta is banning AI, how to back up your chat history, and what it means for users.

Amazon Republic Day Sale 2026: Up to 80% Off on Gadgets & Appliances

Amazon's Great Republic Day Sale 2026 is live with massive discounts on electronics, fashion & home appliances. Get top deals, no-cost EMI & a chance to win a trip.

Amazon Republic Day Sale: iPhone 15, OnePlus Nord 5, iQOO 15 Big Discounts

Get record-low prices on iPhone 15, OnePlus Nord 5, and iQOO 15 during Amazon's Great Republic Day Sale 2025 from Jan 14-18. Details on discounts, bank offers, and early access.

CERT-In Flags High-Risk Dolby Bug on Android, Urges Patch

Indian cybersecurity agency warns of a critical Dolby Audio vulnerability in Android 13/14. Learn how to protect your device with the latest security update.

McKinsey Makes AI Tool Mandatory in Job Interviews for Hiring

McKinsey now requires candidates to use its 'Lilli' AI tool during interviews. Failure to use it could lead to rejection, highlighting a major shift in hiring skills.

Topics

15 Hindus Killed in Bangladesh in 45 Days, Rights Group Reports

A rights group reports escalating violence against Hindus in Bangladesh, with 15 killed in 45 days. Urgent government action and legal reforms are demanded.

Why Pakistan is Trapped Between Saudi Arabia and UAE Rivalry

Analysis of how Saudi-UAE competition for influence leaves Pakistan in a diplomatic bind, impacting its economy and regional stability.

Trump’s Greenland Push Tests NATO Unity Ahead of Election

Donald Trump's serious interest in buying Greenland highlights a transactional foreign policy that could fracture NATO at a critical time for global security.

Trump’s Greenland Purchase Interest Sparks Diplomatic Row with Denmark

US President confirms interest in buying Greenland, but Denmark and Greenland firmly reject the idea. Explore the strategic reasons and the criticism behind the move.

Machado Meets Trump, Gifts Nobel Replica in Venezuela Power Play

Barred Venezuelan opposition leader María Corina Machado's strategic meeting with Donald Trump aims to maintain pressure on Maduro ahead of the July election.

Princess Leila Pahlavi: The Shah’s Daughter Who Died Alone in Exile

The tragic story of Iranian Princess Leila Pahlavi, who fled the 1979 revolution and died by suicide at 31, revealing the human cost of political upheaval.

Zomato’s Viral Job: Rs 25 Lakh Salary for 1-3 Years Experience in Bengaluru

A Zomato job listing offering Rs 25 lakh salary, Rs 20 lakh ESOP, and daily food credits for a role needing just 1-3 years experience goes viral, sparking debate.

India to Evacuate Citizens from Iran; First Flight from Tehran Tomorrow

MEA prepares evacuation flights for Indians in Iran amid Iran-Israel conflict. First flight from Tehran to Delhi scheduled. Embassy issues urgent travel advisory.
spot_img

Related Articles

Popular Categories

spot_imgspot_img