18.1 C
Delhi
Friday, January 16, 2026

WhatsApp Security Flaw Exposed 3.5 Billion Phone Numbers

Key Takeaways

  • WhatsApp security flaw exposed 3.5 billion phone numbers to potential data scraping
  • Researchers accessed profile photos (57% of cases) and profile text (29% of users)
  • Vulnerability existed despite 2017 warnings; fixed with rate-limiting in October 2025
  • Meta confirms no evidence of malicious exploitation; messages remained encrypted

A massive security vulnerability in WhatsApp put approximately 3.5 billion user phone numbers at risk of exposure, according to University of Vienna researchers. The flaw could have become “the largest data leak in history” if exploited by malicious actors.

Security experts found they could access not just phone numbers but also profile photos for 57% of users and profile text information for 29% of accounts. The potential breach would have eclipsed Facebook’s 2021 scraping incident involving 500 million records.

Aljosha Judmayer, one of the study researchers, told WIRED: “To the best of our knowledge, this marks the most extensive exposure of phone numbers and related user data ever documented.”

Notably, WhatsApp and parent company Meta had been alerted about similar vulnerabilities as early as 2017 but failed to take adequate action at that time.

How the WhatsApp Security Flaw Worked

The vulnerability existed in WhatsApp’s contact discovery feature, which normally helps users find contacts already on the platform. Researchers discovered that without effective rate-limiting, this feature could be exploited to scan massive ranges of phone numbers.

Once a number was confirmed as active on WhatsApp, the same method could retrieve publicly available information including:

  • Profile pictures
  • Profile about text
  • Device types
  • Linked companion devices

Meta’s Response and Fix

Meta acknowledged the security issue and collaborated with researchers after they reported it through the Bug Bounty program in April 2025. The company implemented stricter rate-limiting measures by October 2025 to prevent such scraping attacks.

A Meta spokesperson stated: “We are grateful to the University of Vienna researchers for their responsible partnership. This collaboration successfully identified a novel enumeration technique that surpassed our intended limits.”

The company emphasized that user messages remained secure due to WhatsApp’s default end-to-end encryption, and researchers have securely deleted all collected data. Meta confirmed finding no evidence of malicious actors exploiting this vulnerability.

Latest

India’s Scramjet Success: Why Fighter Jets Still Use Conventional Engines

India joins the hypersonic club with scramjet tech. We explain why this breakthrough won't power fighter jets yet and what it means for missiles and space travel.

Meta Bans ChatGPT on WhatsApp from 2026: How to Save Chats

WhatsApp will block ChatGPT and third-party AI tools in 2026. Learn why Meta is banning AI, how to back up your chat history, and what it means for users.

Amazon Republic Day Sale 2026: Up to 80% Off on Gadgets & Appliances

Amazon's Great Republic Day Sale 2026 is live with massive discounts on electronics, fashion & home appliances. Get top deals, no-cost EMI & a chance to win a trip.

Amazon Republic Day Sale: iPhone 15, OnePlus Nord 5, iQOO 15 Big Discounts

Get record-low prices on iPhone 15, OnePlus Nord 5, and iQOO 15 during Amazon's Great Republic Day Sale 2025 from Jan 14-18. Details on discounts, bank offers, and early access.

CERT-In Flags High-Risk Dolby Bug on Android, Urges Patch

Indian cybersecurity agency warns of a critical Dolby Audio vulnerability in Android 13/14. Learn how to protect your device with the latest security update.

Topics

US Lawmaker Calls Pakistan a Failed State, Contrasts with India

Congressman Rich McCormick's speech contrasts India's investment role with Pakistan, which he accuses of harbouring terrorism and being a Chinese client state.

China’s Top Universities Outrank Harvard in Global Research Output

Nature Index 2024 reveals Chinese universities surpass Harvard in research share, signaling a major shift in global science leadership driven by decades of investment.

Michael Bloomberg Warns White House Fed Attacks Are Dangerous Overreach

Billionaire Michael Bloomberg says White House criticism of the Federal Reserve threatens economic stability, could trigger recession, and must stop.

India-Germany Trade Hits €30 Billion: A Strategic Partnership Evolves

Record trade sets the stage for deeper India-Germany collaboration in green tech, AI, and resilient supply chains as global dynamics shift.

SSC GD Constable Final Result 2025 Out: Check List and Next Steps

SSC has declared the GD Constable final result for 26,146 vacancies. Selected candidates must now prepare for document verification and medical tests.

6.0 Magnitude Earthquake Hits Oregon Coast, No Damage Reported

A significant 6.0 magnitude earthquake struck off the Oregon coast. Get the latest details on location, depth, and initial impact reports.

Billionaire Warns US Taiwan Chip Strategy Risks Chinese Invasion

Howard Lutnick says making Taiwan a semiconductor capital makes it a target for China, urging US to focus on domestic production instead.

Noida, Greater Noida Schools Closed Till Jan 17 Due to Cold Wave

Gautam Buddh Nagar district administration extends school closure for classes up to 8 due to severe cold and dense fog. Check details here.
spot_img

Related Articles

Popular Categories

spot_imgspot_img