14.1 C
Delhi
Friday, November 21, 2025

WhatsApp Security Flaw Exposes 3.5 Billion Phone Numbers Globally

WhatsApp Security Flaw Exposes 3.5 Billion Phone Numbers

A critical WhatsApp vulnerability has exposed phone numbers of over 3.5 billion users worldwide, allowing potential harvesting of profile photos, status updates, and personal information through the app’s contact discovery system.

Key Takeaways

  • WhatsApp’s contact discovery mechanism exposed user phone numbers globally
  • Attackers could scrape profile photos, status updates, and personal details
  • Meta claims the issue has been mitigated with no evidence of abuse
  • Security experts call this a wake-up call for phone-based identity systems

How the Vulnerability Works

Researchers from the University of Vienna and SBA Research discovered that WhatsApp’s contact discovery feature, which matches phone numbers from address books to its database, could be exploited to systematically enumerate and collect user information.

“These findings remind us that even mature, widely trusted systems can contain design or implementation flaws that have real-world consequences,” said researcher Gabriel Gegenhuber from the University of Vienna.

“They show that security and privacy are not one-time achievements, but must be continuously re-evaluated as technology evolves.”

Fundamental Design Flaw

Security experts describe the discovery as highlighting a core problem with using phone numbers as digital identities.

“This issue highlights a fundamental problem with WhatsApp’s architecture: the phone number itself is the vulnerability,” said Marijus Briedis, CTO at NordVPN.

“WhatsApp uses numbers as its core identity system, [so] attackers were able to automatically test billions of them and pull back profile details at extraordinary speed.”

Potential Attack Scenarios

With access to phone numbers, profile photos, and status information, cybercriminals could build highly-targeted impersonation attacks and sophisticated phishing campaigns.

“At scale, this becomes a goldmine for scammers, criminals and well-resourced cyber groups,” Briedis noted.

Meta’s Response

Meta, WhatsApp’s parent company, states it has addressed the vulnerability and found no evidence of malicious exploitation.

“We are grateful to the University of Vienna researchers for their responsible partnership and diligence under our Bug Bounty program,” a spokesperson said.

“Importantly, the researchers have securely deleted the data collected as part of the study, and we have found no evidence of malicious actors abusing this vector.”

Related Legal Action

The security flaw discovery follows recent allegations by former WhatsApp security chief Attaullah Baig, who served from 2021 to 2025. Baig filed a lawsuit in September alleging WhatsApp failed to address the hacking and takeover of more than 100,000 accounts daily.

Latest

Google Gemini Can Now Verify AI-Generated Images: How It Works

Learn how Google's new feature helps identify AI-created images using invisible watermark technology, with expanded verification coming soon.

Google Solves AI Text Generation Problem with New Nano Banana Pro Model

Google's new AI image model generates precise, readable text in images, overcoming a major limitation for professional design applications.

Russia, India to Deploy Mutual Ground Stations for Navigation Systems

Russia and India plan mutual deployment of GLONASS and NavIC ground stations to enhance navigation accuracy, with agreements expected during Putin's December visit.

Google Launches AI Scam Detection for Pixel & Enhanced Security Tools

Google unveils AI-powered scam detection for Pixel phones, enhanced verification to replace SMS OTPs, and watermarking for 10B+ AI-generated files to boost digital safety.

Google Launches Nano Banana Pro AI Image Tool for Professionals

Google's new Nano Banana Pro, built on Gemini 3, offers advanced image editing, text handling, and professional controls with tier-based watermarking.

Topics

Petrol Diesel Prices Today November 21: Check Your City Rates

Get latest petrol and diesel prices across 15 Indian cities. Hyderabad petrol at ₹107.46/L, Chandigarh diesel cheapest at ₹82.45/L. Daily updates at 6 AM.

Reliance Stops Russian Crude Imports for Export Refinery Operations

Reliance Industries halts Russian crude imports at Jamnagar export refinery to comply with EU sanctions. Full transition to non-Russian oil completed ahead of schedule.

India Gains Trade Leverage Against US Despite 50% Tariffs

India turns US tariff challenge into negotiation advantage as exports show resilience. Strategic positioning could lead to major trade concessions.

26 E-commerce Giants Declare Platforms Free From Dark Patterns

Flipkart, Zomato, Swiggy and 23 other major platforms complete government audits, eliminating deceptive design practices that manipulate consumers.

ED Attaches ₹1,452 Crore Anil Ambani Group Assets in Fraud Case

Enforcement Directorate seizes properties worth ₹1,452 crore from Anil Ambani group in money laundering probe involving ₹40,185 crore bank loans.

Bloodworms Invert Organs in Seconds: Science Behind Alien-like Ability

Discover how venomous bloodworms explosively turn their organs inside out and what this means for future soft robotics technology.

Earth’s Moon Formed by Collision with Planetary Neighbor Theia

New research reveals Theia, the protoplanet that created our Moon, was Earth's cosmic next-door neighbor with identical chemical composition.

NASA’s Perseverance Finds Possible Meteorite on Mars Surface

Mars rover discovers unusual iron-nickel rock that may be a meteorite from beyond Mars, offering clues about solar system formation.
spot_img

Related Articles

Popular Categories

spot_imgspot_img