{"id":333220,"date":"2025-12-07T17:40:07","date_gmt":"2025-12-07T17:40:07","guid":{"rendered":"https:\/\/www.newsbeep.com\/au\/333220\/"},"modified":"2025-12-07T17:40:07","modified_gmt":"2025-12-07T17:40:07","slug":"scientists-discovered-a-major-security-vulnerability-in-whatsapp","status":"publish","type":"post","link":"https:\/\/www.newsbeep.com\/au\/333220\/","title":{"rendered":"Scientists discovered a major security vulnerability in WhatsApp"},"content":{"rendered":"<p>With more than three billion people opening WhatsApp each day, the app feels like a safe place to talk, share photos, and handle work on the move. Friends trust it. Families depend on it. Businesses run on it. But new academic research shows that the app quietly revealed far more about its users than most people ever expected.<\/p>\n<p>A team of IT security researchers from the <a href=\"https:\/\/www.univie.ac.at\/en\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">University of Vienna<\/a> and SBA Research discovered that WhatsApp could be used to quietly confirm whether a phone number belonged to a real account, nearly anywhere on Earth. Over five months, from December 2024 through April 2025, they tested billions of possible phone numbers. By April, they had confirmed more than 3.5 billion active accounts across 245 countries. That figure is higher than the company\u2019s own public count.<\/p>\n<p>Messages stayed protected the entire time. End to end encryption held. The problem was not what people said to each other. The weakness lay in the simple fact of knowing who used WhatsApp and what could be learned from that alone.<\/p>\n<p>WhatsApp users wrt. to continent, Android vs. iOS use, and profile picture for 3.5B users. (CREDIT: arXiv) How billions of users were uncovered<\/p>\n<p>WhatsApp offers a tool that checks which contacts in a phone\u2019s address book are already on the app. It is meant to make connecting easy. The researchers used that same feature, but through an <a href=\"https:\/\/www.thebrighterside.news\/post\/revolutionary-open-source-technology-connects-with-living-neurons\/\" rel=\"nofollow noopener\" target=\"_blank\">open source<\/a> client rather than the official app. This gave them direct access to WhatsApp\u2019s system.<\/p>\n<p>They wrote a program called \u201clibphonegen\u201d to create realistic phone numbers from real numbering plans in 245 countries. That produced more than 63 billion possible numbers. They then asked WhatsApp one basic question about each number: Is this an account?<\/p>\n<p>Using just one server and five registered accounts, they checked about 7,000 numbers per second. WhatsApp never completely shut them down. Their accounts stayed active. Their internet address was not blocked.<\/p>\n<p>\u201cNormally, a system shouldn\u2019t respond to such a high number of requests in such a short time, particularly when originating from a single source,\u201d said lead author Gabriel Gegenhuber of the University of Vienna. \u201cThis behavior exposed the underlying flaw, which allowed us to issue an effectively unlimited requests to the server and, in doing so, map user data worldwide.\u201d<\/p>\n<p>WhatsApp Use per Capita: At 95\u2009% in South America and 80\u2009% in Europe, a majority of citizens have an active WhatsApp account. (CREDIT: arXiv) What public data quietly reveals<\/p>\n<p>Once a number was confirmed, the system returned data that is public by design. That included the phone number, cryptographic public keys, the account\u2019s creation time, and, if shared by the user, profile photos and \u201cabout\u201d messages.<\/p>\n<p>From that, the team could infer even more. They could tell what kind of <a href=\"https:\/\/www.thebrighterside.news\/post\/study-finds-reducing-smartphone-use-increases-work-satisfaction\/\" rel=\"nofollow noopener\" target=\"_blank\">phone<\/a> a person used, how long their account existed, and whether it was linked to other devices such as laptops or tablets.<\/p>\n<p>This led to the largest known snapshot of a global messaging network. India topped the list with more than 749 million users. Indonesia, Brazil, the United States, and Russia followed. Together, the top ten countries held most of the world\u2019s accounts.<\/p>\n<p>Android phones ruled the platform, making up 81 percent of users. iPhones accounted for the rest. Wealthier regions showed far heavier <a href=\"https:\/\/www.thebrighterside.news\/post\/ai-turns-everyday-videos-into-interactive-3d-worlds-for-games-and-robots\/\" rel=\"nofollow noopener\" target=\"_blank\">iPhone<\/a> use.<\/p>\n<p>More than half of all users had a profile photo. Nearly one in three wrote a short bio. About 9 percent labeled themselves as business accounts. Roughly the same number used at least one linked device.<\/p>\n<p>WhatsApp adoption per continent. Percentage shares are calculated by dividing the number of discovered WhatsApp accounts by the respective population size (per capita) of each continent. (CREDIT: arXiv) Accounts where WhatsApp is banned<\/p>\n<p>The study found active users in countries where WhatsApp is officially blocked.<\/p>\n<p>China had more than 2.3 million accounts. Myanmar showed 1.6 million. Iran already counted about 59 million users before a ban was lifted in December 2024. Within three months, that jumped to more than 67 million. Linked device use tripled.<\/p>\n<p>North Korea, with its tight controls, showed only five accounts.<\/p>\n<p>In places where online speech can bring <a href=\"https:\/\/www.thebrighterside.news\/post\/ai-generated-vr-looks-to-transform-prisoner-rehab-and-the-penal-system\/\" rel=\"nofollow noopener\" target=\"_blank\">punishment<\/a>, even proof of account ownership can put lives at risk.<\/p>\n<p>Faces, locations, and exposure<\/p>\n<p>Millions of users also shared deeply personal details.<\/p>\n<p>Some posted political opinions. Others included faith symbols, sexual identity, or street slang tied to drugs. Many listed email addresses, social media names, or business links.<\/p>\n<p>Distribution of prekey bundle age across our retrieved data. Over 90\u2009% of users have updated their keys within the past month. Consistent with WhatsApp\u2019s account deletion policy, most accounts with keys older than 120 days have been automatically removed. (CREDIT: arXiv) <\/p>\n<p>Profile photos carried their own danger. The researchers downloaded 77 million images from accounts tied to U.S. numbers alone. Automated scans showed two thirds included clear <a href=\"https:\/\/www.thebrighterside.news\/post\/do-ai-generated-faces-look-more-real-than-actual-human-face\/\" rel=\"nofollow noopener\" target=\"_blank\">human faces<\/a>. Others revealed street scenes, homes, or workplaces.<\/p>\n<p>This opens the door to building a reverse phone directory powered by faces. It also makes targeting easier for scammers, stalkers, or hostile governments.<\/p>\n<p>Strange behavior in encryption keys<\/p>\n<p>Messages stayed protected. But the researchers noticed disturbing patterns in how some <a href=\"https:\/\/www.thebrighterside.news\/post\/scientists-create-the-next-generation-of-secure-quantum-communication\/\" rel=\"nofollow noopener\" target=\"_blank\">encryption keys<\/a> were handled.<\/p>\n<p>Each device should have a unique identifier. Instead, 2.3 million keys were reused across almost three million devices. One public key had an even deeper flaw. It belonged to 20 U.S. numbers, and its private key was all zeros.<\/p>\n<p>That points to broken random number creation in some unofficial clients or possible fraud. In rare cases like this, bad actors could pretend to be someone else or secretly add their own devices to accounts.<\/p>\n<p>Old leaks that still matter<\/p>\n<p>To see how long phone data stays valuable, the team tested numbers from a massive <a href=\"https:\/\/www.thebrighterside.news\/post\/facebook-to-shut-down-face-recognition-system-delete-data\/\" rel=\"nofollow noopener\" target=\"_blank\">Facebook<\/a> scrape in 2018 that went public years later. Out of 488 million numbers, more than 280 million still worked on WhatsApp.<\/p>\n<p>In some countries, nearly four in ten active numbers overlapped with the old leak. Once a number escapes into the wild, it may stay useful for criminals for years.<\/p>\n<p>A flaw now addressed<\/p>\n<p>The researchers shared their findings with Meta, WhatsApp\u2019s parent company, before publication. The company confirmed the issue has since been fixed.<\/p>\n<p>\u201cWe are grateful to the University of Vienna researchers for their responsible partnership,\u201d said Nitin Gupta, vice president of engineering at WhatsApp. \u201cThis collaboration successfully identified a novel enumeration technique that surpassed our intended limits. We had already been working on anti-scraping systems, and this study helped confirm their strength.\u201d<\/p>\n<p>\u201cThese findings remind us that even mature, widely trusted systems can contain flaws with real world consequences,\u201d Gegenhuber said. \u201cSecurity and privacy are not one time victories. They must be constantly tested.\u201d<\/p>\n<p>Research findings are available online in the journal <a href=\"https:\/\/arxiv.org\/abs\/2511.20252\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">arXiv<\/a>.<\/p>\n<p>Related Stories<\/p>\n","protected":false},"excerpt":{"rendered":"With more than three billion people opening WhatsApp each day, the app feels like a safe place to&hellip;\n","protected":false},"author":2,"featured_media":333221,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[6],"tags":[64,63,284,8886,112964,1333,337,128,105,2641],"class_list":{"0":"post-333220","1":"post","2":"type-post","3":"status-publish","4":"format-standard","5":"has-post-thumbnail","7":"category-technology","8":"tag-au","9":"tag-australia","10":"tag-cybersecurity","11":"tag-hacking","12":"tag-innovation-news","13":"tag-meta","14":"tag-research","15":"tag-science","16":"tag-technology","17":"tag-whatsapp"},"_links":{"self":[{"href":"https:\/\/www.newsbeep.com\/au\/wp-json\/wp\/v2\/posts\/333220","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.newsbeep.com\/au\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.newsbeep.com\/au\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/au\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/au\/wp-json\/wp\/v2\/comments?post=333220"}],"version-history":[{"count":0,"href":"https:\/\/www.newsbeep.com\/au\/wp-json\/wp\/v2\/posts\/333220\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/au\/wp-json\/wp\/v2\/media\/333221"}],"wp:attachment":[{"href":"https:\/\/www.newsbeep.com\/au\/wp-json\/wp\/v2\/media?parent=333220"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.newsbeep.com\/au\/wp-json\/wp\/v2\/categories?post=333220"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.newsbeep.com\/au\/wp-json\/wp\/v2\/tags?post=333220"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}