Close Menu
Technology Mag

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot
    Under Musk, the Grok disaster was inevitable

    Under Musk, the Grok disaster was inevitable

    January 18, 2026
    Microsoft’s first Windows 11 update of 2026 stopped some computers from shutting down

    Microsoft’s first Windows 11 update of 2026 stopped some computers from shutting down

    January 18, 2026
    Did Coinbase just derail the crypto industry’s political future?

    Did Coinbase just derail the crypto industry’s political future?

    January 18, 2026
    Facebook X (Twitter) Instagram
    Subscribe
    Technology Mag
    Facebook X (Twitter) Instagram YouTube
    • Home
    • News
    • Business
    • Games
    • Gear
    • Reviews
    • Science
    • Security
    • Trending
    • Press Release
    Technology Mag
    Home » A Simple WhatsApp Security Flaw Exposed 3.5 Billion Phone Numbers
    Security

    A Simple WhatsApp Security Flaw Exposed 3.5 Billion Phone Numbers

    News RoomBy News RoomNovember 20, 20253 Mins Read
    Facebook Twitter Pinterest LinkedIn Reddit WhatsApp Email
    A Simple WhatsApp Security Flaw Exposed 3.5 Billion Phone Numbers

    WhatsApp’s mass adoption stems in part from how easy it is to find a new contact on the messaging platform: Add someone’s phone number, and WhatsApp instantly shows whether they’re on the service, and often their profile picture and name, too.

    Repeat that same trick a few billion times with every possible phone number, it turns out, and the same feature can also serve as a convenient way to obtain the cell number of virtually every WhatsApp user on earth—along with, in many cases, profile photos and text that identifies each of those users. The result is a sprawling exposure of personal information for a significant fraction of the world population.

    One group of Austrian researchers have now shown that they were able to use that simple method of checking every possible number in WhatsApp’s contact discovery to extract 3.5 billion users’ phone numbers from the messaging service. For about 57 percent of those users, they also found that they could access their profile photos, and for another 29 percent, the text on their profiles. Despite a previous warning about WhatsApp’s exposure of this data from a different researcher in 2017, they say, the service’s parent company, Meta, still failed to limit the speed or number of contact discovery requests the researchers could make by interacting with WhatsApp’s browser-based app, allowing them to check roughly a hundred million numbers an hour.

    The result would be “the largest data leak in history, had it not been collated as part of a responsibly conducted research study,” as the researchers describe it in a paper documenting their findings.

    “To the best of our knowledge, this marks the most extensive exposure of phone numbers and related user data ever documented,” says Aljosha Judmayer, one of the researchers at the University of Vienna who worked on the study.

    The researchers say they warned Meta about their findings in April and deleted their copy of the 3.5 billion phone numbers. By October, the company had fixed the enumeration problem by enacting a stricter “rate-limiting” measure that prevents the mass-scale contact discovery method the researchers used. But until then, the data exposure could have also been exploited by anyone else using the same scraping technique, adds Max Günther, another researcher from the university who cowrote the paper. “If this could be retrieved by us super easily, others could have also done the same,” he says.

    In a statement to WIRED, Meta thanked the researchers, who reported their discovery through Meta’s “bug bounty” system, and described the exposed data as “basic publicly available information,” since profile photos and text weren’t exposed for users who opted to make it private. “We had already been working on industry-leading anti-scraping systems, and this study was instrumental in stress-testing and confirming the immediate efficacy of these new defenses,” writes Nitin Gupta, vice president of engineering at WhatsApp. Gupta adds, “We have found no evidence of malicious actors abusing this vector. As a reminder, user messages remained private and secure thanks to WhatsApp’s default end-to-end encryption, and no non-public data was accessible to the researchers.”

    Share. Facebook Twitter Pinterest LinkedIn WhatsApp Reddit Email
    Previous ArticleIn Alex Karp’s World, Palantir Is the Underdog
    Next Article Microsoft’s AI-powered copy and paste can now use on-device AI

    Related Posts

    Cloudflare Has Blocked 416 Billion AI Bot Requests Since July 1

    Cloudflare Has Blocked 416 Billion AI Bot Requests Since July 1

    December 6, 2025
    The Louisiana Department of Wildlife and Fisheries Is Detaining People for ICE

    The Louisiana Department of Wildlife and Fisheries Is Detaining People for ICE

    December 5, 2025
    Your Data Might Determine How Much You Pay for Eggs

    Your Data Might Determine How Much You Pay for Eggs

    December 4, 2025
    Russia Wants This Mega Missile to Intimidate the West, but It Keeps Crashing

    Russia Wants This Mega Missile to Intimidate the West, but It Keeps Crashing

    December 4, 2025
    This Hacker Conference Installed a Literal Antivirus Monitoring System

    This Hacker Conference Installed a Literal Antivirus Monitoring System

    December 4, 2025
    Flock Uses Overseas Gig Workers to Build Its Surveillance AI

    Flock Uses Overseas Gig Workers to Build Its Surveillance AI

    December 4, 2025
    Our Picks
    Microsoft’s first Windows 11 update of 2026 stopped some computers from shutting down

    Microsoft’s first Windows 11 update of 2026 stopped some computers from shutting down

    January 18, 2026
    Did Coinbase just derail the crypto industry’s political future?

    Did Coinbase just derail the crypto industry’s political future?

    January 18, 2026
    Kaoss Pad V is the first major upgrade to Korg’s touch-based effects in 13 years

    Kaoss Pad V is the first major upgrade to Korg’s touch-based effects in 13 years

    January 18, 2026
    Here are the 10 deals worth grabbing from Best Buy’s winter sales event

    Here are the 10 deals worth grabbing from Best Buy’s winter sales event

    January 18, 2026
    • Facebook
    • Twitter
    • Pinterest
    • Instagram
    • YouTube
    • Vimeo
    Don't Miss
    Disney deleted a Thread because people kept quoting its movies at it News

    Disney deleted a Thread because people kept quoting its movies at it

    By News RoomJanuary 17, 2026

    ”Share a Disney quote that sums up how you’re feeling right now!”That’s what Disney posted…

    The Setapp Mobile iOS store is shutting down on February 16th

    The Setapp Mobile iOS store is shutting down on February 16th

    January 17, 2026
    The LG C5 and Apple’s M4 Mac Mini are both steeply discounted this weekend

    The LG C5 and Apple’s M4 Mac Mini are both steeply discounted this weekend

    January 17, 2026
    Fear and blogging (and prerelease laptop testing) in Las Vegas

    Fear and blogging (and prerelease laptop testing) in Las Vegas

    January 17, 2026
    Facebook X (Twitter) Instagram Pinterest
    • Privacy Policy
    • Terms of use
    • Advertise
    • Contact
    © 2026 Technology Mag. All Rights Reserved.

    Type above and press Enter to search. Press Esc to cancel.