16.1 C
Delhi
Thursday, November 20, 2025

WhatsApp Security Flaw Exposed 3.5 Billion Phone Numbers

Key Takeaways

  • WhatsApp security flaw exposed 3.5 billion phone numbers to potential data scraping
  • Researchers accessed profile photos (57% of cases) and profile text (29% of users)
  • Vulnerability existed despite 2017 warnings; fixed with rate-limiting in October 2025
  • Meta confirms no evidence of malicious exploitation; messages remained encrypted

A massive security vulnerability in WhatsApp put approximately 3.5 billion user phone numbers at risk of exposure, according to University of Vienna researchers. The flaw could have become “the largest data leak in history” if exploited by malicious actors.

Security experts found they could access not just phone numbers but also profile photos for 57% of users and profile text information for 29% of accounts. The potential breach would have eclipsed Facebook’s 2021 scraping incident involving 500 million records.

Aljosha Judmayer, one of the study researchers, told WIRED: “To the best of our knowledge, this marks the most extensive exposure of phone numbers and related user data ever documented.”

Notably, WhatsApp and parent company Meta had been alerted about similar vulnerabilities as early as 2017 but failed to take adequate action at that time.

How the WhatsApp Security Flaw Worked

The vulnerability existed in WhatsApp’s contact discovery feature, which normally helps users find contacts already on the platform. Researchers discovered that without effective rate-limiting, this feature could be exploited to scan massive ranges of phone numbers.

Once a number was confirmed as active on WhatsApp, the same method could retrieve publicly available information including:

  • Profile pictures
  • Profile about text
  • Device types
  • Linked companion devices

Meta’s Response and Fix

Meta acknowledged the security issue and collaborated with researchers after they reported it through the Bug Bounty program in April 2025. The company implemented stricter rate-limiting measures by October 2025 to prevent such scraping attacks.

A Meta spokesperson stated: “We are grateful to the University of Vienna researchers for their responsible partnership. This collaboration successfully identified a novel enumeration technique that surpassed our intended limits.”

The company emphasized that user messages remained secure due to WhatsApp’s default end-to-end encryption, and researchers have securely deleted all collected data. Meta confirmed finding no evidence of malicious actors exploiting this vulnerability.

Latest

Roblox Implements Facial Age Verification to Protect Children from Adults

Roblox becomes first gaming platform to require facial age checks for chat features, grouping users by age to prevent child-adult interactions amid safety concerns.

Microsoft 365 Copilot Gets AI Agents for Word, Excel, PowerPoint

Microsoft Ignite 2025 reveals AI agents that create documents, spreadsheets, and presentations through natural language commands in Copilot Chat with enhanced security.

Robot Dog Spot Joins 60+ Bomb Squads at Rs 90 Lakh Cost

Boston Dynamics' Spot robot now serves over 60 police departments for bomb disposal and rescue missions, priced from $100,000. Learn about its capabilities and the ethical debate.

Google Gemini 3 Launches in India with Free Jio Access Plan

Get 18 months of Google's advanced Gemini 3 AI free with Jio Unlimited 5G. Learn features and how to claim the Rs 35,100 package.

Google Play Store Awards 2025: Best Apps and Games in India

Discover the top award-winning apps and games on Google Play Store in India for 2025, including AI-powered tools and locally relevant content.

Topics

Vapes 3,000 Times Dirtier Than Toilet Seats, Study Reveals

Laboratory research shows vape mouthpieces harbour dangerous bacteria and fungi. Learn proper cleaning methods to reduce health risks.

Gates Foundation Sells 65% of Microsoft Stake in Major Portfolio Shift

Gates Foundation's Q3 2025 portfolio rebalancing cuts Microsoft stake by 65%, reduces holdings from 25 to 23, and drops portfolio value by $11.2 billion.

AMD, Cisco and Saudi’s Humain Launch AI Data Center Venture with Luma AI as First Client

Major tech partnership to build AI data centers in Middle East, with Luma AI securing entire 100-megawatt capacity in first project targeting 4.5 billion people.

Veefin Appoints Sorabh Dhawan as CEO of PSB Xchange Platform

Sorabh Dhawan to lead PSB Xchange's digital transformation, bringing 18 years of banking expertise to enhance India's supply chain finance ecosystem.

RBI Alert: 7 New Unauthorised Forex Trading Platforms Listed

RBI expands alert list with 7 unauthorised forex trading platforms. Protect your investments by avoiding these unregulated entities and learn safe trading practices.

First Human Kiss Dates Back 21 Million Years, Study Reveals

Groundbreaking Oxford research shows kissing evolved 21 million years ago and ancient humans may have kissed Neanderthals as signs of affection.

L&T to Produce BvS10 Sindhu Armoured Vehicles for Indian Army

L&T wins Indian Army contract to indigenously manufacture BvS10 Sindhu all-terrain armoured vehicles at Hazira facility with BAE Systems support.

India’s Gaganyaan Mission Marks Sputnik Moment in Space Leadership

Astronauts declare India must shape global space governance as Gaganyaan mission advances with 2027 human spaceflight target and international partnerships.
spot_img

Related Articles

Popular Categories

spot_imgspot_img