15.1 C
Delhi
Friday, January 16, 2026

WhatsApp Security Flaw Exposes 3.5 Billion Phone Numbers Globally

WhatsApp Security Flaw Exposes 3.5 Billion Phone Numbers

A critical WhatsApp vulnerability has exposed phone numbers of over 3.5 billion users worldwide, allowing potential harvesting of profile photos, status updates, and personal information through the app’s contact discovery system.

Key Takeaways

  • WhatsApp’s contact discovery mechanism exposed user phone numbers globally
  • Attackers could scrape profile photos, status updates, and personal details
  • Meta claims the issue has been mitigated with no evidence of abuse
  • Security experts call this a wake-up call for phone-based identity systems

How the Vulnerability Works

Researchers from the University of Vienna and SBA Research discovered that WhatsApp’s contact discovery feature, which matches phone numbers from address books to its database, could be exploited to systematically enumerate and collect user information.

“These findings remind us that even mature, widely trusted systems can contain design or implementation flaws that have real-world consequences,” said researcher Gabriel Gegenhuber from the University of Vienna.

“They show that security and privacy are not one-time achievements, but must be continuously re-evaluated as technology evolves.”

Fundamental Design Flaw

Security experts describe the discovery as highlighting a core problem with using phone numbers as digital identities.

“This issue highlights a fundamental problem with WhatsApp’s architecture: the phone number itself is the vulnerability,” said Marijus Briedis, CTO at NordVPN.

“WhatsApp uses numbers as its core identity system, [so] attackers were able to automatically test billions of them and pull back profile details at extraordinary speed.”

Potential Attack Scenarios

With access to phone numbers, profile photos, and status information, cybercriminals could build highly-targeted impersonation attacks and sophisticated phishing campaigns.

“At scale, this becomes a goldmine for scammers, criminals and well-resourced cyber groups,” Briedis noted.

Meta’s Response

Meta, WhatsApp’s parent company, states it has addressed the vulnerability and found no evidence of malicious exploitation.

“We are grateful to the University of Vienna researchers for their responsible partnership and diligence under our Bug Bounty program,” a spokesperson said.

“Importantly, the researchers have securely deleted the data collected as part of the study, and we have found no evidence of malicious actors abusing this vector.”

Related Legal Action

The security flaw discovery follows recent allegations by former WhatsApp security chief Attaullah Baig, who served from 2021 to 2025. Baig filed a lawsuit in September alleging WhatsApp failed to address the hacking and takeover of more than 100,000 accounts daily.

Latest

iQOO Z11 Turbo Launched With 7,600mAh Battery & Snapdragon 8s Gen 3

iQOO Z11 Turbo debuts with a massive battery, 100W charging, and flagship Snapdragon 8s Gen 3 chip. Check price, specs, and launch details.

India’s Scramjet Success: Why Fighter Jets Still Use Conventional Engines

India joins the hypersonic club with scramjet tech. We explain why this breakthrough won't power fighter jets yet and what it means for missiles and space travel.

Meta Bans ChatGPT on WhatsApp from 2026: How to Save Chats

WhatsApp will block ChatGPT and third-party AI tools in 2026. Learn why Meta is banning AI, how to back up your chat history, and what it means for users.

Amazon Republic Day Sale 2026: Up to 80% Off on Gadgets & Appliances

Amazon's Great Republic Day Sale 2026 is live with massive discounts on electronics, fashion & home appliances. Get top deals, no-cost EMI & a chance to win a trip.

Amazon Republic Day Sale: iPhone 15, OnePlus Nord 5, iQOO 15 Big Discounts

Get record-low prices on iPhone 15, OnePlus Nord 5, and iQOO 15 during Amazon's Great Republic Day Sale 2025 from Jan 14-18. Details on discounts, bank offers, and early access.

Topics

Mumbai Voter Turnout Hits 32-Year High in Lok Sabha Elections

Mumbai recorded 55.38% voter turnout in 2024 Lok Sabha polls, its second-highest in 32 years. Analysis reveals what drove the surge and what it means for the city's civic engagement.

Spirit Release Date: Prabhas & Sandeep Reddy Vanga Film Set for Jan 2026

Sandeep Reddy Vanga announces January 10, 2026, as the release date for his pan-India film Spirit, starring Prabhas and Tripti Dimri.

BJP Breaks Sena Fortress, Wins Historic 2026 BMC Election

The BJP-led Mahayuti alliance ends the Thackeray dynasty's 30-year rule over Mumbai's civic body. Analysis on why Shiv Sena (UBT) crumbled and Congress stalled.

Wipro Declares Rs 6 Dividend as Q3 Profit Dips to Rs 3,119 Crore

Wipro announces Rs 6 per share interim dividend for FY25. Q3 net profit falls to Rs 3,119 crore, but order bookings surge 31% year-on-year.

Bhumi Pednekar’s Daldal Teaser Out, Series Premieres April 5 on Prime

Watch the gritty teaser for crime thriller 'Daldal' starring Bhumi Pednekar as a cop. The series premieres on Amazon Prime Video on April 5.

Doctor’s Viral Senate Testimony: “Biologically, Men Cannot Get Pregnant”

Dr Nisha Verma's exchange with a US senator on pregnancy and gender terminology goes viral, highlighting post-Roe reproductive rights debates.

Trump Nominated for Nobel Peace Prize Over Abraham Accords Role

US lawmaker nominates Donald Trump for the Nobel Peace Prize, citing his historic role in brokering the Abraham Accords. This marks his fourth nomination.

US Lawmaker Calls Pakistan a Failed State, Contrasts with India

Congressman Rich McCormick's speech contrasts India's investment role with Pakistan, which he accuses of harbouring terrorism and being a Chinese client state.
spot_img

Related Articles

Popular Categories

spot_imgspot_img