22.1 C
Delhi
Saturday, January 17, 2026

WhatsApp Security Flaw Exposes 3.5 Billion Phone Numbers Globally

WhatsApp Security Flaw Exposes 3.5 Billion Phone Numbers

A critical WhatsApp vulnerability has exposed phone numbers of over 3.5 billion users worldwide, allowing potential harvesting of profile photos, status updates, and personal information through the app’s contact discovery system.

Key Takeaways

  • WhatsApp’s contact discovery mechanism exposed user phone numbers globally
  • Attackers could scrape profile photos, status updates, and personal details
  • Meta claims the issue has been mitigated with no evidence of abuse
  • Security experts call this a wake-up call for phone-based identity systems

How the Vulnerability Works

Researchers from the University of Vienna and SBA Research discovered that WhatsApp’s contact discovery feature, which matches phone numbers from address books to its database, could be exploited to systematically enumerate and collect user information.

“These findings remind us that even mature, widely trusted systems can contain design or implementation flaws that have real-world consequences,” said researcher Gabriel Gegenhuber from the University of Vienna.

“They show that security and privacy are not one-time achievements, but must be continuously re-evaluated as technology evolves.”

Fundamental Design Flaw

Security experts describe the discovery as highlighting a core problem with using phone numbers as digital identities.

“This issue highlights a fundamental problem with WhatsApp’s architecture: the phone number itself is the vulnerability,” said Marijus Briedis, CTO at NordVPN.

“WhatsApp uses numbers as its core identity system, [so] attackers were able to automatically test billions of them and pull back profile details at extraordinary speed.”

Potential Attack Scenarios

With access to phone numbers, profile photos, and status information, cybercriminals could build highly-targeted impersonation attacks and sophisticated phishing campaigns.

“At scale, this becomes a goldmine for scammers, criminals and well-resourced cyber groups,” Briedis noted.

Meta’s Response

Meta, WhatsApp’s parent company, states it has addressed the vulnerability and found no evidence of malicious exploitation.

“We are grateful to the University of Vienna researchers for their responsible partnership and diligence under our Bug Bounty program,” a spokesperson said.

“Importantly, the researchers have securely deleted the data collected as part of the study, and we have found no evidence of malicious actors abusing this vector.”

Related Legal Action

The security flaw discovery follows recent allegations by former WhatsApp security chief Attaullah Baig, who served from 2021 to 2025. Baig filed a lawsuit in September alleging WhatsApp failed to address the hacking and takeover of more than 100,000 accounts daily.

Latest

Elon Musk Shares OpenAI President’s Files, Alleges Fraud Conspiracy

Elon Musk releases internal OpenAI documents, accusing leadership of a 'conspiracy to commit fraud' in an escalating legal and public feud.

Japan Investigates Elon Musk’s Grok AI, Warns Social Media Firms

Japan launches probe into Grok AI's data and content practices, issuing a compliance warning to all social media companies in a major regulatory move.

iQOO Z11 Turbo Launched With 7,600mAh Battery & Snapdragon 8s Gen 3

iQOO Z11 Turbo debuts with a massive battery, 100W charging, and flagship Snapdragon 8s Gen 3 chip. Check price, specs, and launch details.

Microsoft Cuts Staff Library, 1,500 Azure Jobs in AI Push

Microsoft replaces employee library access with AI experiences and cuts 1,500 Azure jobs as part of a restructuring focused on cloud and artificial intelligence.

Grimes Sues Elon Musk’s xAI Over Grok Deepfakes, Says She Lives in Fear

Musician Grimes files lawsuit against Elon Musk's AI company, alleging its Grok chatbot created explicit deepfakes, sparking a major legal battle over AI abuse.

Topics

Elon Musk Shares OpenAI President’s Files, Alleges Fraud Conspiracy

Elon Musk releases internal OpenAI documents, accusing leadership of a 'conspiracy to commit fraud' in an escalating legal and public feud.

Japan Investigates Elon Musk’s Grok AI, Warns Social Media Firms

Japan launches probe into Grok AI's data and content practices, issuing a compliance warning to all social media companies in a major regulatory move.

Trump Threatened Denmark with Tariffs Over Greenland Purchase Bid

Donald Trump reveals he considered tariffs and reduced protection to pressure Denmark into selling strategic Greenland, citing Russian and Chinese threats.

Putin Warns of ‘Catastrophic’ War in Calls with Israel, Iran Leaders

Russian President urges Netanyahu and Pezeshkian to de-escalate tensions, warning further conflict could lead to catastrophic violence across the Middle East.

RIL Q3 Profit Rises 11% to ₹19,641 Crore, Beats Estimates

Reliance Industries posts strong Q3 results with profit up 10.9%, EBITDA growth of 16.7%, and robust performance across all business segments.

Budget 2026: Education Sector Demands Focus on Skills and Jobs

Industry and academia seek higher funding for skill development, NEP implementation, and tax incentives in the upcoming Union Budget to boost employability.

Mumbai Voter Turnout Hits 32-Year High in Lok Sabha Elections

Mumbai recorded 55.38% voter turnout in 2024 Lok Sabha polls, its second-highest in 32 years. Analysis reveals what drove the surge and what it means for the city's civic engagement.

Indian Scientists Uncover Cell’s Life-or-Death Decision Mechanism

Breakthrough research reveals how cells choose survival or self-destruction under stress, opening new paths to treat cancer, heart attacks, and Alzheimer's.
spot_img

Related Articles

Popular Categories

spot_imgspot_img